This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijacking / Redirection

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello everybody!

I have a little problem with my Internet-browser.
Below I placed the log-file from my computer.
I'd be thankful, if anyone could check it and give me further advice (-s).

***********************************************


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:53:27, on 26.07.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACService.exe
C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Programme\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Programme\Gemeinsame Dateien\LightScribe\LSSrvc.exe
C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Programme\Norton AntiVirus\Engine\18.6.0.29\ccSvcHst.exe
C:\Programme\Norton PC Checkup\Engine\2.0.6.11\SymcPCCULaunchSvc.exe
C:\Programme\Norton PC Checkup\Engine\2.0.6.11\ccSvcHst.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Programme\samsung\Samsung Network Manager\SNMWLANService.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Programme\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Programme\Norton PC Checkup\Engine\2.0.6.11\ccSvcHst.exe
C:\Programme\Norton AntiVirus\Engine\18.6.0.29\ccSvcHst.exe
C:\WINDOWS\system32\dllhost.exe
C:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Programme\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe
C:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ArcCon.ac
C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe
C:\Programme\iTunes\iTunesHelper.exe
C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\WI371A~1\Datamngr\DATAMN~1.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\Messenger\msmsgs.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIFDE.EXE
C:\Programme\W3i\InstallIQUpdater\InstallIQUpdater.exe
C:\Programme\iPod\bin\iPodService.exe
C:\Programme\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programme\Mozilla Firefox\firefox.exe
C:\Programme\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\msiexec.exe
C:\Programme\Mozilla Firefox\plugin-container.exe
C:\Dokumente und Einstellungen\Sveta\Lokale Einstellungen\Anwendungsdaten\Google\Google Talk Plugin\googletalkplugin.exe
C:\Programme\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Dokumente und Einstellungen\Sveta\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://de.search.yahoo.com/?fr=w3i&typ…731,16992,0,6,0
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,First Home Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R3 - URLSearchHook: (no name) - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: IEPlugin Class - {11222041-111B-46E3-BD29-EFB2449479B1} - C:\PROGRA~1\ArcSoft\VIDEOD~1\ARCURL~1.DLL
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Programme\Norton AntiVirus\Engine\18.6.0.29\IPS\IPSBHO.DLL
O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Programme\Epson Software\Easy Photo Print\EPTBL.dll
O2 - BHO: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI371A~1\Datamngr\ToolBar\searchqudtx.dll
O2 - BHO: UrlHelper Class - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll
O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\Programme\IDM\QUICKfind\PlugIns\IEHelp.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programme\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programme\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Programme\Epson Software\Easy Photo Print\EPTBL.dll
O3 - Toolbar: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI371A~1\Datamngr\ToolBar\searchqudtx.dll
O4 - HKLM\..\Run: [EPSON Stylus Photo R240 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAHE.EXE /P30 "EPSON Stylus Photo R240 Series" /O6 "USB004" /M "Stylus Photo R240"
O4 - HKLM\..\Run: [HPLJ Config] C:\Programme\Hewlett-Packard\hp LaserJet 1010 Series\SetConfig.exe -c Direct -p DOT4_001 -pn "hp LaserJet 1010 Series Driver" -n 0 -l 1031 -sl 120000
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programme\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [StatusClient] C:\Programme\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [TomcatStartup] C:\Programme\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe
O4 - HKLM\..\Run: [EEventManager] C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programme\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [DATAMNGR] C:\PROGRA~1\WI371A~1\Datamngr\DATAMN~1.EXE
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKLM\..\RunOnce: [InnoSetupRegFile.0000000001] "C:\WINDOWS\is-Q6GUP.exe" /REG /REGSVRMODE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programme\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Dokumente und Einstellungen\Sveta\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [EPSON SX210 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIFDE.EXE /FU "C:\WINDOWS\TEMP\E_S2E7.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [Startw3i] C:\Programme\PC Speed Maximizer\Startw3i.exe
O4 - HKCU\..\Run: [InstallIQUpdater] "C:\Programme\W3i\InstallIQUpdater\InstallIQUpdater.exe" /silent /autorun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - http://axis.udm.net/activex/AMC.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Dienst "Bonjour" (Bonjour Service) - Apple Inc. - C:\Programme\Bonjour\mDNSResponder.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Google Update Service (gupdate1c9fd69e5bf5f8c) (gupdate1c9fd69e5bf5f8c) - Google Inc. - C:\Programme\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update-Dienst (gupdatem) (gupdatem) - Google Inc. - C:\Programme\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Programme\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programme\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programme\Gemeinsame Dateien\LightScribe\LSSrvc.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Programme\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: Norton AntiVirus (NAV) - Symantec Corporation - C:\Programme\Norton AntiVirus\Engine\18.6.0.29\ccSvcHst.exe
O23 - Service: Norton PC Checkup Application Launcher - Symantec Corporation - C:\Programme\Norton PC Checkup\Engine\2.0.6.11\SymcPCCULaunchSvc.exe
O23 - Service: Common Client Job Manager Service (PCCUJobMgr) - Symantec Corporation - C:\Programme\Norton PC Checkup\Engine\2.0.6.11\ccSvcHst.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Samsung Update Plus - Unknown owner - C:\Programme\Samsung\Samsung Update Plus\SLUBackgroundService.exe
O23 - Service: SNM WLAN Service - Unknown owner - C:\Programme\samsung\Samsung Network Manager\SNMWLANService.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Programme\Yahoo!\SoftwareUpdate\YahooAUService.exe
O24 - Desktop Component 0: (no name) - http://www.izhneftemash.ru/foto/image.aspx…w=450&h=320

–
End of file - 12607 bytes
Hello Mimino and Welcome to WhatTheTech Forums

My name is BlackPegasus.

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for
    further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to
    get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out
    the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 3 days your thread will be closed.
  • Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to
    ensure that I am giving you the best possible advice.
  • This may cause a delay in response time, but I will do my best to keep it as short as possible.
  • I will reply back shortly with instructions.
Hello Mimino

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise, this will be a team effort.
This may cause a delay, but I will do my best to keep it as short as possible. Please bear with me, I will post back to you as soon as I can.


IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
      Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

    =======================
    NEXT

    Please download aswMBR ( 511KB ) to your desktop.
    • Double click the aswMBR.exe icon to run it
    • Click the Scan button to start the scan
    • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.
    =======================
    Please include in your next reply:
    1. Any problem executing the instructions?
    2. OTL log and Extras.Txt
    3. aswMBR log
Hello BlackPegasus! Tahnk you so much for answering my post!

After scanning with OTL, I have just the OTL.txt file on my desktop, there is no Extras.txt-file.

Here is the log by OTL:


OTL logfile created on: 27.07.2011 18:44:42 - Run 2
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Dokumente und Einstellungen\Sveta\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy

1,87 Gb Total Physical Memory | 0,78 Gb Available Physical Memory | 41,86% Memory free
4,54 Gb Paging File | 3,61 Gb Available in Paging File | 79,49% Paging File free
Paging file location(s): C:\pagefile.sys 2877 2877 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 94,22 Gb Total Space | 57,84 Gb Free Space | 61,39% Space Free | Partition Type: NTFS

Computer Name: SVETLANA | User Name: Sveta | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Dokumente und Einstellungen\Sveta\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Dokumente und Einstellungen\Sveta\Lokale Einstellungen\Anwendungsdaten\Google\Google Talk Plugin\googletalkplugin.exe (Google)
PRC - C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Programme\W3i\InstallIQUpdater\InstallIQUpdater.exe (W3i, LLC)
PRC - C:\Programme\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Bandoo Media, inc)
PRC - C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Programme\Norton AntiVirus\Engine\18.6.0.29\ccsvchst.exe (Symantec Corporation)
PRC - C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Programme\Norton PC Checkup\Engine\2.0.6.11\SymcPCCULaunchSvc.exe (Symantec Corporation)
PRC - C:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
PRC - C:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ArcCon.ac (ArcSoft Inc.)
PRC - C:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Programme\Norton PC Checkup\Engine\2.0.6.11\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Programme\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
PRC - C:\Programme\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FATIFDE.EXE (SEIKO EPSON CORPORATION)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Gemeinsame Dateien\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Programme\Samsung\Samsung Network Manager\SNMWLANService.exe ()
PRC - C:\WINDOWS\system32\PAStiSvc.exe ()
PRC - C:\Programme\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe (Hewlett-Packard)
PRC - C:\Programme\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe ()


========== Modules (SafeList) ==========

MOD - C:\Dokumente und Einstellungen\Sveta\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (MBAMService) – C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (NAV) – C:\Programme\Norton AntiVirus\Engine\18.6.0.29\ccSvcHst.exe (Symantec Corporation)
SRV - (Apple Mobile Device) – C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (Norton PC Checkup Application Launcher) – C:\Programme\Norton PC Checkup\Engine\2.0.6.11\SymcPCCULaunchSvc.exe (Symantec Corporation)
SRV - (ACDaemon) – C:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (McComponentHostService) – C:\Programme\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (PCCUJobMgr) – C:\Programme\Norton PC Checkup\Engine\2.0.6.11\ccSvcHst.exe (Symantec Corporation)
SRV - (YahooAUService) – C:\Programme\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (Samsung Update Plus) – C:\Programme\Samsung\Samsung Update Plus\SLUBackgroundService.exe ()
SRV - (LightScribeService) – C:\Programme\Gemeinsame Dateien\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (SNM WLAN Service) – C:\Programme\samsung\Samsung Network Manager\SNMWLANService.exe ()
SRV - (IDriverT) – C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (STI Simulator) – C:\WINDOWS\system32\PAStiSvc.exe ()
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (ose) – C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (eeCtrl) – C:\Programme\Gemeinsame Dateien\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Programme\Gemeinsame Dateien\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\System32\Drivers\NAV\1206000.01D\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\WINDOWS\system32\drivers\NAV\1206000.01D\SRTSPX.SYS (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\NAV\1206000.01D\SYMTDI.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\NAV\1206000.01D\SYMEFA.SYS (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\NAV\1206000.01D\SYMDS.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\NAV\1206000.01D\Ironx86.SYS (Symantec Corporation)
DRV - (IDSxpx86) – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\IPSDefs\20101021.003\IDSXpx86.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20101025.002\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20101025.002\NAVENG.SYS (Symantec Corporation)
DRV - (BHDrvx86) – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\BASHDefs\20101001.001\BHDrvx86.sys (Symantec Corporation)
DRV - (w200obex) – C:\WINDOWS\system32\drivers\w200obex.sys (MCCI)
DRV - (w200mdm) – C:\WINDOWS\system32\drivers\w200mdm.sys (MCCI)
DRV - (w200mdfl) – C:\WINDOWS\system32\drivers\w200mdfl.sys (MCCI)
DRV - (w200bus) Sony Ericsson W200 driver (WDM) – C:\WINDOWS\system32\drivers\w200bus.sys (MCCI)
DRV - (VVBackd5) – C:\WINDOWS\System32\drivers\VVBackd5.sys ()
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (ZDCNDIS5) – C:\WINDOWS\ZDCndis5.sys (ZDC., Inc. (ZDC))
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
DRV - (DNSeFilter) – C:\WINDOWS\system32\drivers\SamsungEDS.SYS (Samsung Electronics,.LTD)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (SSB2413) – C:\WINDOWS\system32\drivers\SSB2413.sys (Atheros Communications, Inc.)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (DOSMEMIO) – C:\WINDOWS\system32\MEMIO.SYS ()
DRV - (BALU) – C:\WINDOWS\system32\drivers\balu.sys ()
DRV - (SUEPD) – C:\WINDOWS\system32\drivers\SUE_PD.sys (Samsung)
DRV - (rtl8139) NT-Treiber für Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (RITCPT) – C:\WINDOWS\System32\drivers\RITCPT.SYS ()
DRV - (FBAPI) – C:\WINDOWS\system32\drivers\FBAPI.sys ()
DRV - (pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://de.search.yahoo.com/?fr=w3i&typ;…731,16992,0,6,0
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search Results"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;="
FF - prefs.js..browser.search.order.1: "Search Results"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/406"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..keyword.URL: "http://dts.search-results.com/sr?src=ffb&appid;=102&systemid;=406&q;="

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Programme\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Programme\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Content Upload Plugin,version=1.0.0: C:\Programme\DivX\DivX Content Uploader\npUpload.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Programme\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Programme\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Programme\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Programme\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Programme\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Programme\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Programme\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\[removed]/YahooActiveXPluginBridge;version=1.0.0.1: C:\PROGRA~1\Yahoo!\Common\npyaxmpb.dll File not found
FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Dokumente und Einstellungen\Sveta\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=8: C:\Dokumente und Einstellungen\Sveta\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.2.183.39\npGoogleOneClick8.dll File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Dokumente und Einstellungen\Sveta\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Mozilla\Firefox Extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2007.08.22 14:11:27 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\IPSFFPlgn\ [2011.07.11 20:27:53 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{B728AB94-9BC7-49b7-B76A-422BB31B2FD0}: C:\Programme\ArcSoft\Video Downloader\Plugin_FireFox [2010.11.28 15:17:07 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Programme\Mozilla Firefox\components [2011.06.22 21:45:18 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2011.06.29 18:37:36 | 000,000,000 | —D | M]

[2011.07.26 17:47:59 | 000,000,000 | —D | M] (No name found) – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\Mozilla\Extensions
[2011.07.26 18:21:14 | 000,000,000 | —D | M] (No name found) – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\Mozilla\Firefox\Profiles\mhq82cpm.default\extensions
[2010.04.05 22:21:09 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\Mozilla\Firefox\Profiles\mhq82cpm.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2007.08.25 13:18:45 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\Mozilla\Firefox\Profiles\mhq82cpm.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2011.07.26 18:46:21 | 000,000,000 | —D | M] (Searchqu Toolbar) – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\Mozilla\Firefox\Profiles\mhq82cpm.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}
[2011.07.26 17:47:18 | 000,002,501 | —- | M] () – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\Mozilla\Firefox\Profiles\mhq82cpm.default\searchplugins\SearchResults.xml
[2011.07.26 17:47:59 | 000,000,000 | —D | M] (No name found) – C:\Programme\Mozilla Firefox\extensions
[2010.09.30 18:58:35 | 000,000,000 | —D | M] (Java Console) – C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010.10.22 00:06:00 | 000,000,000 | —D | M] (Java Console) – C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011.06.17 20:12:01 | 000,000,000 | —D | M] (Java Console) – C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
File not found (No name found) –
[2011.07.11 20:27:53 | 000,000,000 | —D | M] (Symantec IPS) – C:\DOKUMENTE UND EINSTELLUNGEN\ALL USERS\ANWENDUNGSDATEN\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\IPSFFPLGN
[2010.04.24 14:39:59 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAMME\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011.06.22 21:45:14 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Programme\mozilla firefox\components\browsercomps.dll
[2011.05.04 04:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Programme\mozilla firefox\plugins\npdeployJava1.dll
[2010.07.12 18:33:56 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Programme\mozilla firefox\plugins\npwachk.dll
[2011.05.07 21:11:29 | 000,001,392 | —- | M] () – C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.05.07 21:11:29 | 000,002,252 | —- | M] () – C:\Programme\mozilla firefox\searchplugins\bing.xml
[2011.05.07 21:11:29 | 000,001,153 | —- | M] () – C:\Programme\mozilla firefox\searchplugins\eBay-de.xml
[2011.05.07 21:11:29 | 000,006,805 | —- | M] () – C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.07.26 17:47:18 | 000,002,501 | —- | M] () – C:\Programme\mozilla firefox\searchplugins\SearchResults.xml
[2011.05.07 21:11:29 | 000,001,178 | —- | M] () – C:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.05.07 21:11:29 | 000,001,105 | —- | M] () – C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml

O1 HOSTS File: ([2010.09.25 17:23:33 | 000,000,820 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (IEPlugin Class) - {11222041-111B-46E3-BD29-EFB2449479B1} - C:\Programme\ArcSoft\Video Downloader\ArcURLRecord.dll (ArcSoft, Inc.)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Programme\Skype\Phone\IEPlugin\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Programme\Norton AntiVirus\Engine\18.6.0.29\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Programme\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Programme\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Programme\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Bandoo Media, inc)
O2 - BHO: (QUICKfind BHO Object) - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\Programme\IDM\QUICKfind\PlugIns\IEHelp.dll ()
O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programme\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Programme\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Programme\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programme\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (Norton AntiVirus) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Norton AntiVirus) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - File not found
O3 - HKCU\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programme\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe ARM] C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [DATAMNGR] C:\Programme\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Bandoo Media, inc)
O4 - HKLM..\Run: [EEventManager] C:\Programme\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [EPSON Stylus Photo R240 Series] File not found
O4 - HKLM..\Run: [HPLJ Config] C:\Programme\Hewlett-Packard\hp LaserJet 1010 Series\SetConfig.exe (Hewlett-Packard Inc.)
O4 - HKLM..\Run: [StatusClient] C:\Programme\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe (Hewlett-Packard)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TomcatStartup] C:\Programme\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe (Hewlett-Packard)
O4 - HKCU..\Run: [EPSON SX210 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIFDE.EXE (SEIKO EPSON CORPORATION)
O4 - HKCU..\Run: [InstallIQUpdater] C:\Programme\W3i\InstallIQUpdater\InstallIQUpdater.exe (W3i, LLC)
O4 - HKCU..\Run: [Startw3i] File not found
O4 - HKLM..\RunOnce: [InnoSetupRegFile.0000000001] C:\WINDOWS\is-Q6GUP.exe ()
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Programme\Skype\Phone\IEPlugin\SkypeIEPlugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} http://axis.udm.net/activex/AMC.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Gemeinsame Dateien\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll) - C:\Programme\Windows iLivid Toolbar\Datamngr\datamngr.dll (Bandoo Media, inc)
O20 - AppInit_DLLs: (C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll) - C:\Programme\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Bandoo Media, inc)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 () - http://www.izhneftemash.ru/foto/image.aspx…w=450&h;=320
O24 - Desktop Components:1 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.10.09 20:18:53 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{26e7d15c-270e-11df-9a52-0013773197b5}\Shell - "" = AutoRun
O33 - MountPoints2\{26e7d15c-270e-11df-9a52-0013773197b5}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{26e7d15c-270e-11df-9a52-0013773197b5}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{26e7d160-270e-11df-9a52-0013773197b5}\Shell - "" = AutoRun
O33 - MountPoints2\{26e7d160-270e-11df-9a52-0013773197b5}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{26e7d160-270e-11df-9a52-0013773197b5}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{35bc88f8-700a-11db-a6b2-0013773197b5}\Shell - "" = AutoRun
O33 - MountPoints2\{35bc88f8-700a-11db-a6b2-0013773197b5}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{35bc88f8-700a-11db-a6b2-0013773197b5}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O33 - MountPoints2\{432b284c-279c-11df-9a58-0013773197b5}\Shell - "" = AutoRun
O33 - MountPoints2\{432b284c-279c-11df-9a58-0013773197b5}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{432b284c-279c-11df-9a58-0013773197b5}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011.07.26 22:05:19 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2011.07.26 22:00:34 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\vlc
[2011.07.26 21:57:02 | 000,000,000 | —D | C] – C:\Programme\VideoLAN
[2011.07.26 21:29:02 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\Sveta\Eigene Dateien\Carmen-Kirsten2
[2011.07.26 20:51:51 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011.07.26 20:51:51 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011.07.26 20:51:51 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011.07.26 19:19:15 | 001,915,904 | —- | C] (AVAST Software) – C:\Dokumente und Einstellungen\Sveta\Desktop\aswMBR.exe
[2011.07.26 19:16:38 | 000,579,584 | —- | C] (OldTimer Tools) – C:\Dokumente und Einstellungen\Sveta\Desktop\OTL.exe
[2011.07.26 19:00:12 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\searchquband
[2011.07.26 19:00:12 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\Sveta\AppData
[2011.07.26 18:47:24 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\PriceGong
[2011.07.26 18:47:06 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\RegistryKeys
[2011.07.26 18:46:21 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\Sveta\Lokale Einstellungen\Anwendungsdaten\PackageAware
[2011.07.26 18:46:20 | 000,000,000 | -HSD | C] – C:\WINDOWS\System32\AI_RecycleBin
[2011.07.26 18:46:20 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\FinalTorrent
[2011.07.26 17:52:11 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Bandoo
[2011.07.26 17:51:58 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\Sveta\Lokale Einstellungen\Anwendungsdaten\Ilivid Player
[2011.07.26 17:51:55 | 000,000,000 | —D | C] – C:\Programme\Bandoo
[2011.07.26 17:48:50 | 000,000,000 | -H-D | C] – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{9CD61942-8DA1-4781-925C-4FE1471E0820}
[2011.07.26 17:48:28 | 000,000,000 | —D | C] – C:\Programme\iLivid
[2011.07.26 17:47:38 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\searchqutoolbar
[2011.07.26 17:47:22 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\boost_interprocess
[2011.07.26 17:47:18 | 000,000,000 | —D | C] – C:\Programme\Windows iLivid Toolbar
[2011.07.26 17:37:02 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\Sveta\Eigene Dateien\My Downloads
[2011.07.26 17:34:57 | 000,000,000 | —D | C] – C:\Programme\W3i
[2011.07.26 17:34:57 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\W3i
[2011.07.26 17:34:57 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\InstallIQ Updater
[2011.07.26 17:34:35 | 000,000,000 | —D | C] – C:\Programme\FinalTorrent
[2011.07.26 17:33:57 | 000,000,000 | —D | C] – C:\Programme\Free Offers from Freeze.com
[2011.07.26 17:33:42 | 000,000,000 | —D | C] – C:\Programme\Yahoo!

========== Files - Modified Within 30 Days ==========

[2011.07.27 18:47:10 | 000,000,418 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{17A5E491-0DBB-40A1-85C3-BC4969F1A904}.job
[2011.07.27 18:27:01 | 000,001,210 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3771985245-72322722-229232620-1006UA.job
[2011.07.27 18:22:01 | 000,001,090 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011.07.26 21:59:41 | 000,000,691 | —- | M] () – C:\Dokumente und Einstellungen\All Users\Desktop\VLC media player.lnk
[2011.07.26 21:55:57 | 021,073,936 | —- | M] () – C:\Dokumente und Einstellungen\Sveta\Desktop\vlc-1.1.11-win32.exe
[2011.07.26 21:36:38 | 000,012,645 | —- | M] () – C:\Dokumente und Einstellungen\Sveta\Desktop\Carmen.Kirsten.mp4
[2011.07.26 21:31:20 | 000,000,825 | —- | M] () – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\mainhst.zgh
[2011.07.26 21:22:05 | 000,000,424 | —- | M] () – C:\WINDOWS\zipgenius.xml
[2011.07.26 21:22:00 | 000,001,086 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011.07.26 21:20:27 | 000,004,096 | —- | M] () – C:\Dokumente und Einstellungen\Sveta\Desktop\Carmen-Kirsten1-6.rar
[2011.07.26 21:20:20 | 044,613,265 | —- | M] () – C:\Dokumente und Einstellungen\Sveta\Desktop\Carmen.Kirsten.mp4.part
[2011.07.26 19:20:04 | 001,915,904 | —- | M] (AVAST Software) – C:\Dokumente und Einstellungen\Sveta\Desktop\aswMBR.exe
[2011.07.26 19:16:41 | 000,579,584 | —- | M] (OldTimer Tools) – C:\Dokumente und Einstellungen\Sveta\Desktop\OTL.exe
[2011.07.26 18:56:30 | 000,709,968 | —- | M] () – C:\WINDOWS\is-Q6GUP.exe
[2011.07.26 18:56:30 | 000,012,782 | —- | M] () – C:\WINDOWS\is-Q6GUP.msg
[2011.07.26 18:56:30 | 000,000,415 | —- | M] () – C:\WINDOWS\is-Q6GUP.lst
[2011.07.26 18:51:43 | 000,000,352 | —- | M] () – C:\WINDOWS\tasks\FinalTorrent Update Checker.job
[2011.07.26 18:49:09 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011.07.26 18:48:32 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011.07.26 18:48:27 | 2011,316,224 | -HS- | M] () – C:\hiberfil.sys
[2011.07.23 22:37:15 | 003,701,431 | —- | M] () – C:\Dokumente und Einstellungen\Sveta\Desktop\Nightlifeguide_2010.pdf
[2011.07.22 21:52:53 | 000,000,190 | -H– | M] () – C:\WINDOWS\NsNetScan.ini
[2011.07.15 22:47:05 | 000,274,168 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011.07.14 20:58:04 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011.07.12 20:53:05 | 000,002,509 | —- | M] () – C:\Dokumente und Einstellungen\Sveta\Desktop\Microsoft Office Word 2003.lnk
[2011.07.06 19:52:42 | 000,041,272 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011.07.06 19:52:42 | 000,022,712 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011.06.30 18:40:09 | 000,463,100 | —- | M] () – C:\WINDOWS\System32\perfh007.dat
[2011.06.30 18:40:09 | 000,444,902 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011.06.30 18:40:09 | 000,086,168 | —- | M] () – C:\WINDOWS\System32\perfc007.dat
[2011.06.30 18:40:09 | 000,072,778 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011.06.29 18:37:39 | 000,001,709 | —- | M] () – C:\Dokumente und Einstellungen\All Users\Desktop\Adobe Reader 9.lnk
[2011.06.29 18:36:05 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011.06.28 15:27:00 | 000,001,158 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3771985245-72322722-229232620-1006Core.job

========== Files Created - No Company Name ==========

[2011.07.26 21:59:39 | 000,000,691 | —- | C] () – C:\Dokumente und Einstellungen\All Users\Desktop\VLC media player.lnk
[2011.07.26 21:54:34 | 021,073,936 | —- | C] () – C:\Dokumente und Einstellungen\Sveta\Desktop\vlc-1.1.11-win32.exe
[2011.07.26 21:36:37 | 000,012,645 | —- | C] () – C:\Dokumente und Einstellungen\Sveta\Desktop\Carmen.Kirsten.mp4
[2011.07.26 21:20:27 | 000,004,096 | —- | C] () – C:\Dokumente und Einstellungen\Sveta\Desktop\Carmen-Kirsten1-6.rar
[2011.07.26 21:08:11 | 044,613,265 | —- | C] () – C:\Dokumente und Einstellungen\Sveta\Desktop\Carmen.Kirsten.mp4.part
[2011.07.26 18:56:30 | 000,709,968 | —- | C] () – C:\WINDOWS\is-Q6GUP.exe
[2011.07.26 18:56:30 | 000,012,782 | —- | C] () – C:\WINDOWS\is-Q6GUP.msg
[2011.07.26 18:56:30 | 000,000,415 | —- | C] () – C:\WINDOWS\is-Q6GUP.lst
[2011.07.26 17:51:50 | 001,524,112 | —- | C] () – C:\WINDOWS\System32\bandoolmx.dll
[2011.07.26 17:35:27 | 000,000,352 | —- | C] () – C:\WINDOWS\tasks\FinalTorrent Update Checker.job
[2011.07.23 22:37:15 | 003,701,431 | —- | C] () – C:\Dokumente und Einstellungen\Sveta\Desktop\Nightlifeguide_2010.pdf
[2011.01.04 19:08:54 | 000,000,000 | —- | C] () – C:\WINDOWS\EEventManager.INI
[2010.12.27 21:09:19 | 000,111,932 | —- | C] () – C:\WINDOWS\System32\EPPICPrinterDB.dat
[2010.12.27 21:09:19 | 000,031,053 | —- | C] () – C:\WINDOWS\System32\EPPICPattern131.dat
[2010.12.27 21:09:19 | 000,027,417 | —- | C] () – C:\WINDOWS\System32\EPPICPattern121.dat
[2010.12.27 21:09:19 | 000,026,154 | —- | C] () – C:\WINDOWS\System32\EPPICPattern1.dat
[2010.12.27 21:09:19 | 000,024,903 | —- | C] () – C:\WINDOWS\System32\EPPICPattern3.dat
[2010.12.27 21:09:19 | 000,021,390 | —- | C] () – C:\WINDOWS\System32\EPPICPattern5.dat
[2010.12.27 21:09:19 | 000,020,148 | —- | C] () – C:\WINDOWS\System32\EPPICPattern2.dat
[2010.12.27 21:09:19 | 000,011,811 | —- | C] () – C:\WINDOWS\System32\EPPICPattern4.dat
[2010.12.27 21:09:19 | 000,004,943 | —- | C] () – C:\WINDOWS\System32\EPPICPattern6.dat
[2010.12.27 21:09:19 | 000,001,146 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_DU.dat
[2010.12.27 21:09:19 | 000,001,139 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_PT.dat
[2010.12.27 21:09:19 | 000,001,139 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_BP.dat
[2010.12.27 21:09:19 | 000,001,136 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_ES.dat
[2010.12.27 21:09:19 | 000,001,129 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_FR.dat
[2010.12.27 21:09:19 | 000,001,129 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_CF.dat
[2010.12.27 21:09:19 | 000,001,120 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_IT.dat
[2010.12.27 21:09:19 | 000,001,107 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_GE.dat
[2010.12.27 21:09:19 | 000,001,104 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_EN.dat
[2010.12.27 21:09:19 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2010.10.18 11:04:35 | 000,000,825 | —- | C] () – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\mainhst.zgh
[2010.09.25 13:28:09 | 000,000,000 | —- | C] () – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\N360BUOptions.ini
[2010.09.17 17:29:30 | 000,039,268 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2010.08.24 21:24:33 | 000,000,032 | —- | C] () – C:\WINDOWS\cd-start.INI
[2010.03.31 12:57:38 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2010.03.06 14:16:18 | 000,000,000 | —- | C] () – C:\WINDOWS\prestopm.INI
[2010.03.06 14:08:41 | 000,000,029 | —- | C] () – C:\WINDOWS\DEBUGSM.INI
[2010.03.06 14:08:01 | 000,000,190 | -H– | C] () – C:\WINDOWS\NsNetScan.ini
[2010.03.06 13:55:36 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\IPPCPUID.DLL
[2010.03.06 13:55:36 | 000,000,105 | —- | C] () – C:\WINDOWS\UMXADDIN.INI
[2010.03.06 13:55:36 | 000,000,093 | —- | C] () – C:\WINDOWS\PM20.INI
[2010.03.06 13:55:14 | 000,011,776 | —- | C] () – C:\WINDOWS\System32\pmsbfn32.dll
[2010.03.06 13:53:33 | 000,000,074 | —- | C] () – C:\WINDOWS\PMINI.ini
[2010.03.04 07:55:42 | 000,000,355 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2009.07.05 13:32:15 | 000,001,759 | —- | C] () – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\QTSBandwidthCache
[2008.10.31 21:21:40 | 000,019,117 | —- | C] () – C:\WINDOWS\hplj1010.ini
[2008.10.31 21:20:58 | 000,000,375 | —- | C] () – C:\WINDOWS\hpbvspst.ini
[2008.10.31 21:20:56 | 000,000,998 | —- | C] () – C:\WINDOWS\hpbvnstp.ini
[2008.10.31 21:20:48 | 000,000,212 | R— | C] () – C:\WINDOWS\System32\hpbvnstp.dat
[2008.10.31 21:20:47 | 000,196,608 | R— | C] () – C:\WINDOWS\System32\hpbvnstp.dll
[2008.10.26 23:52:09 | 000,001,753 | —- | C] () – C:\WINDOWS\System32\Vadim_KBD.ini
[2007.12.09 17:26:37 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2007.08.31 20:34:15 | 000,001,140 | —- | C] () – C:\WINDOWS\mozver.dat
[2007.08.31 15:10:01 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\InsDrvZD.dll
[2007.08.31 15:10:01 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\ZyDelReg.exe
[2007.08.31 15:10:01 | 000,015,872 | —- | C] () – C:\WINDOWS\System32\InsDrvZD64.DLL
[2007.08.31 15:09:50 | 000,001,162 | —- | C] () – C:\WINDOWS\System32\W32N55.INI
[2007.07.26 04:53:34 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2007.07.26 04:49:28 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2007.05.15 16:24:53 | 000,016,393 | —- | C] () – C:\WINDOWS\LxFrame.ini
[2007.05.15 16:24:35 | 000,000,031 | —- | C] () – C:\WINDOWS\LxTrans.INI
[2007.03.25 15:16:06 | 000,372,736 | —- | C] () – C:\WINDOWS\System32\hpzidi01.dll
[2007.03.25 15:16:05 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\hpzids01.dll
[2007.03.24 23:11:46 | 000,000,182 | —- | C] () – C:\WINDOWS\System32\EBPPORT4.DAT
[2007.03.24 22:11:58 | 000,000,468 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2007.03.24 22:11:58 | 000,000,030 | —- | C] () – C:\WINDOWS\System32\brss01a.ini
[2007.03.24 22:11:58 | 000,000,027 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2007.03.17 20:06:56 | 000,000,084 | —- | C] () – C:\WINDOWS\winamp.ini
[2007.03.11 09:14:56 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\PAStiSvc.exe
[2007.02.17 20:33:17 | 000,000,417 | —- | C] () – C:\WINDOWS\vbface.INI
[2007.02.11 03:15:52 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2007.02.04 22:59:21 | 000,000,400 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007.01.21 20:50:54 | 000,038,912 | —- | C] () – C:\Dokumente und Einstellungen\Sveta\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007.01.15 04:18:25 | 000,001,753 | —- | C] () – C:\WINDOWS\System32\Sveta_KBD.ini
[2007.01.15 04:17:32 | 000,000,138 | —- | C] () – C:\Dokumente und Einstellungen\Sveta\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2007.01.14 03:51:46 | 000,000,725 | —- | C] () – C:\WINDOWS\aolback.exe.lnk
[2007.01.14 03:49:10 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2007.01.14 03:40:50 | 000,179,831 | —- | C] () – C:\WINDOWS\System32\drivers\VVBackd5.sys
[2007.01.14 03:38:21 | 000,001,753 | —- | C] () – C:\WINDOWS\System32\Viktor_KBD.ini
[2006.11.12 17:40:22 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\FKStampPainter20.dll
[2006.11.10 09:41:11 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006.10.10 04:56:21 | 000,121,995 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2006.10.10 04:53:10 | 000,000,420 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2006.10.10 04:52:49 | 000,463,100 | —- | C] () – C:\WINDOWS\System32\perfh007.dat
[2006.10.10 04:52:49 | 000,269,480 | —- | C] () – C:\WINDOWS\System32\perfi007.dat
[2006.10.10 04:52:49 | 000,086,168 | —- | C] () – C:\WINDOWS\System32\perfc007.dat
[2006.10.10 04:52:49 | 000,034,478 | —- | C] () – C:\WINDOWS\System32\perfd007.dat
[2006.10.10 04:52:18 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2006.10.10 04:52:16 | 000,444,902 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2006.10.10 04:52:16 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2006.10.10 04:52:16 | 000,072,778 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2006.10.10 04:52:16 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2006.10.10 04:52:15 | 000,004,486 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2006.10.10 04:52:13 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2006.10.10 04:52:12 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2006.10.10 04:52:05 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2006.10.10 04:52:05 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2006.10.10 04:52:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2006.10.10 04:51:54 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2006.10.09 21:08:33 | 000,004,544 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006.10.09 21:07:37 | 000,274,168 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2006.10.09 20:54:14 | 000,000,135 | R— | C] () – C:\WINDOWS\System32\lngEng.ini
[2006.10.09 20:54:14 | 000,000,117 | —- | C] () – C:\WINDOWS\System32\lngKor.ini
[2006.10.09 20:53:44 | 000,208,896 | —- | C] () – C:\WINDOWS\SetDisplayResolution.exe
[2006.10.09 20:40:47 | 000,043,512 | —- | C] () – C:\WINDOWS\System32\drivers\RITCPT.SYS
[2006.10.09 20:40:39 | 000,005,088 | —- | C] () – C:\WINDOWS\System32\drivers\FBAPI.sys
[2006.10.09 20:40:39 | 000,001,755 | —- | C] () – C:\WINDOWS\System32\Administrator_KBD.ini
[2006.10.09 20:40:39 | 000,001,697 | —- | C] () – C:\WINDOWS\System32\MagicKBD.INI
[2006.10.09 20:40:36 | 000,003,425 | —- | C] () – C:\WINDOWS\System32\KBDR.INI
[2006.10.09 20:40:36 | 000,002,741 | —- | C] () – C:\WINDOWS\System32\KBDD.INI
[2006.10.09 20:40:36 | 000,002,699 | —- | C] () – C:\WINDOWS\System32\KBDO.INI
[2006.10.09 20:40:36 | 000,002,699 | —- | C] () – C:\WINDOWS\System32\KBDC.INI
[2006.10.09 20:40:36 | 000,002,606 | —- | C] () – C:\WINDOWS\System32\KBDB.INI
[2006.10.09 20:40:36 | 000,002,236 | —- | C] () – C:\WINDOWS\System32\KBDQ.INI
[2006.10.09 20:40:36 | 000,001,956 | —- | C] () – C:\WINDOWS\System32\KBDE.INI
[2006.10.09 20:40:36 | 000,001,885 | —- | C] () – C:\WINDOWS\System32\KBDP.INI
[2006.10.09 20:40:36 | 000,001,857 | —- | C] () – C:\WINDOWS\System32\KBDUU.INI
[2006.10.09 20:40:36 | 000,001,835 | —- | C] () – C:\WINDOWS\System32\KBDG.INI
[2006.10.09 20:40:36 | 000,001,835 | —- | C] () – C:\WINDOWS\System32\KBDA.INI
[2006.10.09 20:40:36 | 000,001,834 | —- | C] () – C:\WINDOWS\System32\KBDU.INI
[2006.10.09 20:40:36 | 000,001,819 | —- | C] () – C:\WINDOWS\System32\KBDN.INI
[2006.10.09 20:40:36 | 000,001,699 | —- | C] () – C:\WINDOWS\System32\KBDT.INI
[2006.10.09 20:40:36 | 000,001,697 | —- | C] () – C:\WINDOWS\System32\KBDV.INI
[2006.10.09 20:40:36 | 000,001,522 | —- | C] () – C:\WINDOWS\System32\KBDS.INI
[2006.10.09 20:40:36 | 000,001,476 | —- | C] () – C:\WINDOWS\System32\KBDF.INI
[2006.10.09 20:38:15 | 000,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2006.10.09 20:38:08 | 000,028,672 | —- | C] () – C:\WINDOWS\SamsungBluetooth.exe
[2006.10.09 20:38:08 | 000,000,508 | —- | C] () – C:\WINDOWS\SamsungBluetooth.ini
[2006.10.09 20:36:57 | 000,274,432 | —- | C] () – C:\WINDOWS\System32\MagicQ.exe
[2006.10.09 20:36:57 | 000,249,856 | —- | C] () – C:\WINDOWS\System32\WLANUpdate.exe
[2006.10.09 20:36:57 | 000,217,088 | —- | C] () – C:\WINDOWS\System32\mdslmmax.exe
[2006.10.09 20:36:57 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\RemoveWLAN.exe
[2006.10.09 20:36:57 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\ACUClose.exe
[2006.10.09 20:36:25 | 000,000,860 | —- | C] () – C:\WINDOWS\System32\drivers\HDACfg.dat
[2006.10.09 20:36:21 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2006.10.09 20:36:21 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2006.10.09 20:31:03 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\drivers\Marker.exe
[2006.10.09 20:31:02 | 000,004,300 | —- | C] () – C:\WINDOWS\System32\MEMIO.SYS
[2006.10.09 20:21:46 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2006.10.09 20:14:20 | 000,021,740 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2006.10.06 18:43:16 | 000,208,896 | —- | C] () – C:\WINDOWS\System32\LXPrnUtil10.dll
[2006.09.29 15:12:12 | 000,303,104 | —- | C] () – C:\WINDOWS\System32\dnt27VC8.dll
[2006.09.24 21:04:42 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\dntvmc27VC8.dll
[2006.09.24 21:03:32 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\dntvm27VC8.dll
[2006.09.21 13:53:28 | 000,282,679 | —- | C] () – C:\WINDOWS\System32\dnt27.dll
[2006.09.21 13:52:24 | 000,077,882 | —- | C] () – C:\WINDOWS\System32\dntvmc27.dll
[2006.09.21 13:52:14 | 000,077,881 | —- | C] () – C:\WINDOWS\System32\dntvm27.dll
[2006.07.06 21:21:44 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\AVSAudioWideStereoDMO.dll
[2006.07.06 21:21:44 | 000,003,628 | —- | C] () – C:\WINDOWS\System32\cmtl.dat
[2006.07.06 21:21:42 | 000,081,920 | —- | C] () – C:\WINDOWS\System32\AVSAudioAmp.dll
[2005.11.09 12:13:48 | 000,282,624 | —- | C] () – C:\WINDOWS\System32\dnt27VC7.dll
[2005.11.09 12:11:46 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\dntvmc27VC7.dll
[2005.11.09 12:11:30 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\dntvm27VC7.dll
[2005.08.05 14:26:04 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005.07.15 12:47:44 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\drivers\balu.sys
[2005.05.04 13:00:06 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\MMedia10VC7.dll
[2005.01.25 16:15:42 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\PA207USD.DLL
[2004.08.17 16:57:24 | 000,327,680 | —- | C] () – C:\WINDOWS\System32\QFClient2.dll
[2004.05.06 14:07:32 | 000,241,664 | —- | C] () – C:\WINDOWS\System32\dnt26VC7.dll
[2004.05.06 14:05:04 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\dntvmc26VC7.dll
[2004.05.06 14:04:42 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\dntvm26VC7.dll
[2003.09.05 12:25:54 | 000,237,623 | —- | C] () – C:\WINDOWS\System32\dnt26.dll
[2003.09.05 12:25:52 | 000,073,785 | —- | C] () – C:\WINDOWS\System32\dntvm26.dll
[2003.09.05 12:03:30 | 000,077,882 | —- | C] () – C:\WINDOWS\System32\dntvmc26.dll
[2003.07.14 17:10:57 | 000,094,274 | —- | C] () – C:\WINDOWS\System32\HPBHEALR.DLL
[2003.02.20 18:53:42 | 000,005,702 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001.12.12 11:41:36 | 000,041,472 | —- | C] () – C:\WINDOWS\System32\W32btstp.dll
[2001.12.12 11:41:36 | 000,025,088 | —- | C] () – C:\WINDOWS\System32\W32btxlt.dll
[2001.10.10 08:57:58 | 000,073,786 | —- | C] () – C:\WINDOWS\System32\dntvmc23.dll
[2001.10.10 08:57:58 | 000,061,497 | —- | C] () – C:\WINDOWS\System32\dntvm23.dll
[2001.03.07 08:02:30 | 000,229,431 | —- | C] () – C:\WINDOWS\System32\dnt23.dll

========== LOP Check ==========

[2011.07.26 17:52:11 | 000,000,000 | —D | M] – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Bandoo
[2011.07.26 18:49:50 | 000,000,000 | —D | M] – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\boost_interprocess
[2007.05.15 16:21:32 | 000,000,000 | —D | M] – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\BTrieve
[2010.12.27 21:25:10 | 000,000,000 | —D | M] – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\EPSON
[2007.05.15 16:20:36 | 000,000,000 | —D | M] – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Lexware
[2011.02.25 23:13:33 | 000,000,000 | —D | M] – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\recknagel-mediathek
[2010.12.27 21:20:46 | 000,000,000 | —D | M] – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\UDL
[2007.01.14 03:51:31 | 000,000,000 | —D | M] – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Viewpoint
[2011.07.26 17:34:57 | 000,000,000 | —D | M] – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\W3i
[2010.03.08 12:09:09 | 000,000,000 | —D | M] – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\WinZipSE
[2011.04.09 18:10:10 | 000,000,000 | —D | M] – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011.07.26 18:46:33 | 000,000,000 | -H-D | M] – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{9CD61942-8DA1-4781-925C-4FE1471E0820}
[2009.07.09 23:13:35 | 000,000,000 | —D | M] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1
[2010.09.12 20:14:42 | 000,000,000 | —D | M] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\BSplayer PRO
[2009.01.04 22:03:18 | 000,000,000 | —D | M] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\cald2
[2011.07.22 21:54:02 | 000,000,000 | —D | M] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\Canon
[2007.03.10 20:37:40 | 000,000,000 | —D | M] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\cld3
[2010.12.28 17:34:49 | 000,000,000 | —D | M] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\Epson
[2011.07.26 21:30:57 | 000,000,000 | —D | M] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\FinalTorrent
[2010.08.09 23:13:30 | 000,000,000 | —D | M] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\Leadertech
[2007.05.15 16:31:12 | 000,000,000 | —D | M] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\Lexware
[2010.09.21 15:43:15 | 000,000,000 | —D | M] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\Mario Schneider
[2011.06.17 00:06:38 | 000,000,000 | —D | M] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\mh-software
[2010.03.06 14:08:00 | 000,000,000 | —D | M] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\NewSoft
[2010.09.26 13:01:42 | 000,000,000 | —D | M] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\Opera
[2011.07.26 18:47:24 | 000,000,000 | —D | M] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\PriceGong
[2011.06.08 06:57:03 | 000,000,000 | —D | M] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\PrintCreations
[2010.12.03 22:00:35 | 000,000,000 | —D | M] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\Radio France
[2011.07.26 18:47:06 | 000,000,000 | —D | M] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\RegistryKeys
[2011.07.26 19:00:12 | 000,000,000 | —D | M] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\searchquband
[2011.07.26 19:00:27 | 000,000,000 | —D | M] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\searchqutoolbar
[2007.05.01 12:52:40 | 000,000,000 | —D | M] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\Snowmint Creative Solutions LLC
[2010.09.16 21:52:04 | 000,000,000 | —D | M] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\Tific
[2010.10.18 11:05:38 | 000,000,000 | —D | M] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\ZipGenius
[2011.07.26 18:51:43 | 000,000,352 | —- | M] () – C:\WINDOWS\Tasks\FinalTorrent Update Checker.job
[2011.07.27 18:47:10 | 000,000,418 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{17A5E491-0DBB-40A1-85C3-BC4969F1A904}.job

========== Purity Check ==========



< End of report >
Hello Mimino

Please open OTL.

  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, click the None button near the top (it may looked greyed out)
  • In the Extra Registry section change it to All
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open 2 notepad windows, OTL.Txt and Extra.txt. Please post the Extra.txt.


Did you run the aswMBR scan? Please post the results of that scan too.
=============
Please include in your next reply:
1. Any problem executing the instructions?
2. OTL.Txt and Extra.txt.
3. aswMBR log
Hello, BlackPegasus! Sorry for my belated answer! Yes, it seems that I still need your help :( Will continue with your instructions immediately!
Hello BlackPegasus!

Here are the reports by OTL-Scan:

1.) Extras.Txt:

OTL Extras logfile created on: 30.07.2011 22:28:28 - Run 3
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Dokumente und Einstellungen\Sveta\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy

1,87 Gb Total Physical Memory | 0,66 Gb Available Physical Memory | 35,08% Memory free
4,54 Gb Paging File | 3,44 Gb Available in Paging File | 75,84% Paging File free
Paging file location(s): C:\pagefile.sys 2877 2877 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 94,22 Gb Total Space | 54,34 Gb Free Space | 57,68% Space Free | Partition Type: NTFS

Computer Name: SVETLANA | User Name: Sveta | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

========== Extra Registry (All) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.chm [@ = chm.file] – C:\WINDOWS\hh.exe (Microsoft Corporation)
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] – C:\WINDOWS\System32\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] – C:\WINDOWS\System32\mshta.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Programme\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.inf [@ = inffile] – C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.ini [@ = inifile] – C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] – C:\WINDOWS\System32\rundll32.exe (Microsoft Corporation)
.js [@ = JSFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.jse [@ = JSEFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.reg [@ = regfile] – C:\WINDOWS\regedit.exe (Microsoft Corporation)
.txt [@ = txtfile] – C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.vbe [@ = VBEFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = Opera.HTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] – "%1" %*
batfile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] – "C:\WINDOWS\hh.exe" %1 (Microsoft Corporation)
cmdfile – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] – "%1" %*
cmdfile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
helpfile [open] – winhlp32.exe %1 (Microsoft Corporation)
hlpfile [open] – %SystemRoot%\System32\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] – C:\WINDOWS\system32\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile – "C:\Programme\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Programme\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Programme\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Programme\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Programme\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] – "C:\Programme\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
inffile [open] – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] – "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile – %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] – %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile – %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] – %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile – %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
regfile [open] – regedit.exe "%1" (Microsoft Corporation)
regfile [merge] – Reg Error: Key error.
regfile [print] – %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
txtfile [open] – %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] – %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] – %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile – %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
vbefile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbefile [print] – %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
vbsfile – %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
vbsfile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbsfile [print] – %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
wsffile – %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
wsffile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
wsffile [print] – %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
wshfile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Programme\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Programme\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] – "C:\Programme\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Programme\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Programme\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Programme\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Programme\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Programme\Gemeinsame Dateien\aol\ACS\AOLacsd.exe" = C:\Programme\Gemeinsame Dateien\aol\ACS\AOLacsd.exe:*:Enabled:AOL
"C:\Programme\Gemeinsame Dateien\aol\ACS\AOLDial.exe" = C:\Programme\Gemeinsame Dateien\aol\ACS\AOLDial.exe:*:Enabled:AOL
"C:\Programme\AOL 9.0\waol.exe" = C:\Programme\AOL 9.0\waol.exe:*:Enabled:AOL 9.0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test – (Microsoft Corporation)
"C:\Programme\Gemeinsame Dateien\aol\ACS\AOLacsd.exe" = C:\Programme\Gemeinsame Dateien\aol\ACS\AOLacsd.exe:*:Enabled:AOL
"C:\Programme\Gemeinsame Dateien\aol\ACS\AOLDial.exe" = C:\Programme\Gemeinsame Dateien\aol\ACS\AOLDial.exe:*:Enabled:AOL
"C:\Programme\AOL 9.0\waol.exe" = C:\Programme\AOL 9.0\waol.exe:*:Enabled:AOL 9.0
"C:\Programme\Google\Google Talk\googletalk.exe" = C:\Programme\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk
"C:\Programme\Yahoo!\Messenger\YahooMessenger.exe" = C:\Programme\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger
"C:\Programme\Yahoo!\Messenger\YServer.exe" = C:\Programme\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server
"C:\Programme\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe" = C:\Programme\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe:*:Disabled:javaw – ()
"C:\Programme\NewSoft\Presto! PageManager 6\NetGroup.exe" = C:\Programme\NewSoft\Presto! PageManager 6\NetGroup.exe:*:Enabled:NewSoft Network Group – (NewSoft Technology Corporation)
"C:\Programme\Java\jre6\bin\java.exe" = C:\Programme\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Dokumente und Einstellungen\Sveta\Lokale Einstellungen\Anwendungsdaten\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Dokumente und Einstellungen\Sveta\Lokale Einstellungen\Anwendungsdaten\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin – (Google)
"C:\Dokumente und Einstellungen\Sveta\Lokale Einstellungen\Temp\7zS253.tmp\SymNRT.exe" = C:\Dokumente und Einstellungen\Sveta\Lokale Einstellungen\Temp\7zS253.tmp\SymNRT.exe:*:Enabled:Norton Removal Tool
"C:\Programme\Opera\opera.exe" = C:\Programme\Opera\opera.exe:*:Enabled:Opera Internet Browser – (Opera Software)
"C:\Programme\Epson Software\Event Manager\EEventManager.exe" = C:\Programme\Epson Software\Event Manager\EEventManager.exe:*:Enabled:EEventManager Application – (SEIKO EPSON CORPORATION)
"C:\Programme\Google\Google Earth\plugin\geplugin.exe" = C:\Programme\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth – (Google)
"C:\Programme\FinalTorrent\FinalTorrent.EXE" = C:\Programme\FinalTorrent\FinalTorrent.EXE:*:Enabled:FinalTorrent – (Bitberry Software)
"C:\Programme\FinalTorrent\FTCheckForUpdates.exe" = C:\Programme\FinalTorrent\FTCheckForUpdates.exe:*:Enabled:FinalTorrent Update Checker – (Bitberry Software)
"C:\Programme\Windows iLivid Toolbar\Datamngr\ToolBar\dtUser.exe" = C:\Programme\Windows iLivid Toolbar\Datamngr\ToolBar\dtUser.exe:*:Enabled:DTX broker – (Visicom Media Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{007B37D9-0C45-4202-834B-DD5FAAE99D63}" = ArcSoft Print Creations - Slimline Card
"{01A1A019-E1D8-482A-BE17-5E118D17C0A0}" = ArcSoft Print Creations - Brochures & Flyers
"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
"{15EE79F4-4ED1-4267-9B0F-351009325D7D}" = HP Software Update
"{17283B95-21A8-4996-97DA-547A48DB266F}" = DisplayManager
"{17CA6206-7109-4426-8EE0-1BD0BE54BCC9}" = Management Center
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = PowerStarter
"{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)
"{22E95014-3038-4909-8708-48AE7FEFBF05}" = DSL Connection Manager
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java™ 6 Update 26
"{26A24AE4-039D-4CA4-87B4-2F83216021F0}" = Java™ 6 Update 21
"{28DA872A-0848-48CF-B749-19A198157A2A}" = mDriver
"{292C47B2-8DB7-47BF-896C-C3C5EE8108C4}" = hp LaserJet 1010 Series
"{2A697B53-0DE3-42DA-B41D-C3F804B1C538}" = iTunes
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{2DC94AFD-A6E2-4AB4-9132-4A3F8E07B386}" = Apple Application Support
"{2F5006EE-BFE5-4715-B2EC-F82EB2FF130D}" = ArcSoft MediaImpression
"{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}" = TrayApp
"{32D6A58F-9659-446C-BBFC-E6F2B41F24DC}" = Magic Doctor
"{350C97B3-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{363188E4-1A27-4DE6-BA48-823D2E205385}" = ArcSoft Scan-n-Stitch Deluxe
"{37530151-56A6-4CE4-9F9F-CE1F5A1356C6}" = ArcSoft Panorama Maker 4
"{3CE47E6B-AE27-4E40-AC54-329EED96B933}" = ArcSoft Print Creations - Funhouse II
"{3D5E5C0A-5B36-4F98-99A7-287F7DBDCE03}" = Skype Plugin Manager
"{40DA94AF-34B7-4BA7-A37F-26F899C031FF}" = ArcSoft PhotoStudio Darkroom 2
"{48F22622-1CC2-4A83-9C1E-644DD96F832D}" = Epson Event Manager
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}" = Adobe® Photoshop® Album Starter Edition 3.0
"{56589DFE-0C29-4DFE-8E42-887B771ECD23}" = ArcSoft Print Creations - Photo Book
"{56F8AFC3-FA98-4ff1-9673-8A026CBF85BE}" = WebReg
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{580183A6-FF92-11D5-9294-0050BA073EEC}" = Presto! PageManager 6
"{593AFFA4-D08E-4272-BABB-420949D32A10}" = QUICKfind
"{5D1C82E7-7EC0-4404-A8AD-36C3B444BC34}" = ArcSoft Print Creations - Poster Creator
"{5E7893B4-B73E-47D6-AEA8-1AF111E479CB}" = Lexware business office pro 2007 (Demo)
"{5F26311C-B135-4F7F-B11E-8E650F83651E}" = DeviceFunctionQFolder
"{669A032D-4E28-3D11-BB26-8AD5D51EFE87}" = Google Talk Plugin
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{685707A4-911C-468D-BFC4-64A50E5E3A0C}" = Samsung Update Plus
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{6F730513-8688-4C3C-90A3-6B9792CE2EF3}" = Samsung Battery Manager
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{79221CA7-A39A-4AE5-A558-B5D928393FC4}_is1" = File Extractor v0.9.9
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7B9A0203-AFB3-4C59-B844-0E41DC299848}" = Lexware business office pro 2007 (Demo)
"{7C5B4583-7CBF-4289-B195-03B553959DEA}" = VoiceOver Kit
"{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}" = EPSON Web-To-Page
"{87C2248A-C7DD-49ED-9BCD-B312A9D0819E}" = Epson Easy Photo Print 2
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8D15E1B2-D2B7-4A17-B44B-D2DDE5981406}" = iLivid
"{8D70145A-3BD3-4DBF-9CBF-223EF4A43257}" = ATI Parental Control & Encoder
"{90110407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{9591C049-5CAE-4E89-A8D9-191F1899628B}" = ArcSoft Print Creations - Funhouse
"{95F875CC-1B85-43E6-B3E0-13EA04F3D995}" = ArcSoft Print Creations - Photo Prints
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F7AF7CD-E3D0-4C68-A3BA-C76C359B3AA8}" = LightScribe 1.4.105.1
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A999CE76-D054-4684-80C7-53FC9243E019}" = EasyBox
"{A9FE59F0-5BFA-4FDF-84C6-F45457715379}" = InstallIQ Updater
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{ABB14904-A11B-4F42-996C-80FD608A0F17}" = Samsung EDS
"{AC76BA86-7AD7-1031-7B44-A94000000001}" = Adobe Reader 9.4.5 - Deutsch
"{B0D83FCD-9D42-43ED-8315-250326AADA02}" = ArcSoft Print Creations - Scrapbook
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B18B7901-4025-4BFF-9DA2-BCC45F594DE2}" = Atheros WLAN Client
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}" = Google Earth
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B996AE66-10DB-4ac5-B151-E8B4BFBC42FC}" = BufferChm
"{BA7AF70A-F81B-40EF-9268-741A7DE3D608}" = AVStation Premium 3.75
"{BCE46757-7674-4416-BEDB-68205A60409E}" = Canon CanoScan Toolbox 4.1
"{BD723E53-A42C-4702-AA04-1D74A0311590}" = Magic Keyboard
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C73F2967-062E-48F2-A462-D335B8950183}" = Safari
"{C765D9FF-4A34-4BF1-9F91-E9A3C60C86FC}" = ArcSoft VideoImpression 2
"{C8B44566-839A-459C-A73D-49764CE216CC}" = ArcSoft Video Downloader
"{CA9ED5E4-1548-485B-A293-417840060158}" = ArcSoft Print Creations - Photo Calendar
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DEA48EFD-22C1-4CD6-B887-EB2E6B2E4735}" = Samsung Network Manager 2.0
"{E12DA139-1E5B-46DB-BAEA-683DC9F27CBC}" = ATI Catalyst Control Center
"{E2EE273D-E111-4FFD-ACD4-78E1D35E01D2}" = ArcSoft Photo Book Screen Saver
"{E6B4117F-AC59-4B13-9274-EB136E8897EE}" = ArcSoft Print Creations - Album Page
"{E78BFA60-5393-4C38-82AB-E8019E464EB4}" = Microsoft .NET Framework 1.1 German Language Pack
"{EA103B64-C0E4-4C0E-A506-751590E1653D}" = SolutionCenter
"{EC3B598C-1151-4191-B5B4-A9072ADE6259}_is1" = ZipGenius 6 (6.3.1.2501)
"{EF99C14B-17C2-4994-B5C1-EB204A343A6F}" = User's Guide
"{F03EC055-F34E-4F6B-A684-8A370E11A304}" = ArcSoft Print Creations
"{F04F9557-81A9-4293-BC49-2C216FA325A7}" = ArcSoft Print Creations - Greeting Card
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F4C2E5F5-2970-45f4-ABD3-C180C4D961C4}" = Status
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Agere Systems Soft Modem" = SENS LT56ADW Modem
"All ATI Software" = ATI - Dienstprogramm zur Deinstallation der Software
"AOL YGP Screensaver" = AOL Meine Fotos Bildschirmschoner
"ATI Display Driver" = ATI Display Driver
"Bandoo" = Bandoo
"EPSON Printer and Utilities" = EPSON-Drucker-Software
"EPSON Scanner" = EPSON Scan
"Epson Stylus SX210_SX410_TX210_TX410 Benutzerhandbuch" = Epson Stylus SX210_SX410_TX210_TX410 Handbuch
"EPSON SX210 Series" = EPSON SX210 Series Printer Uninstall
"FinalTorrent_is1" = FinalTorrent 2011
"HP Imaging Device Functions" = HP Imaging Device Functions 5.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center & Imaging Support Tools 5.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"iLivid" = iLivid
"InstallShield_{685707A4-911C-468D-BFC4-64A50E5E3A0C}" = Samsung Update Plus
"InstallShield_{BA7AF70A-F81B-40EF-9268-741A7DE3D608}" = AVStation Premium 3.75
"InstallShield_{DEA48EFD-22C1-4CD6-B887-EB2E6B2E4735}" = Samsung Network Manager 2.0
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware Version 1.51.1.1800
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 5.0 (x86 de)" = Mozilla Firefox 5.0 (x86 de)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSDOrganizer_is1" = MSD Organizer 7.50
"MSMONEYV70" = Microsoft Money 99
"NAV" = Norton AntiVirus
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NortonPCCheckup" = Norton PC Checkup
"Opera 11.11.2109" = Opera 11.11
"ProInst" = Intel® PROSet/Wireless Software
"Radio France_is1" = Radio France 1.1.1
"Recknagel-Mediathek_is1" = Recknagel-Mediathek CD 2.1
"RestoreIT!" = Recover Pro
"Searchqu 406 MediaBar" = Windows iLivid Toolbar
"Skype_is1" = Skype 3.0
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"ToolBand.SkypeIEToolbarToolbar" = Skype add-on for IE
"Uninstall_is1" = Uninstall 1.0.0.1
"Universal Extractor_is1" = Universal Extractor 1.6.1
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VLC media player 1.1.11
"WIC" = Windows Imaging Component
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinZip Self-Extractor" = WinZip Self-Extractor
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
"Winamp Detect" = Winamp Erkennungs-Plug-in

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 30.07.2011 06:32:54 | Computer Name = SVETLANA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 16806171

Error - 30.07.2011 13:49:00 | Computer Name = SVETLANA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 30.07.2011 13:49:00 | Computer Name = SVETLANA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 2031

Error - 30.07.2011 13:49:00 | Computer Name = SVETLANA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2031

Error - 30.07.2011 14:15:06 | Computer Name = SVETLANA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 30.07.2011 14:15:06 | Computer Name = SVETLANA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1568593

Error - 30.07.2011 14:15:06 | Computer Name = SVETLANA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1568593

Error - 30.07.2011 15:05:01 | Computer Name = SVETLANA | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung aswmbr.exe, Version 0.9.8.977, fehlgeschlagenes
Modul ntdll.dll, Version 5.1.2600.6055, Fehleradresse 0x00011689.

Error - 30.07.2011 16:24:08 | Computer Name = SVETLANA | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung aswmbr.exe, Version 0.9.8.977, fehlgeschlagenes
Modul ntdll.dll, Version 5.1.2600.6055, Fehleradresse 0x00011689.

Error - 30.07.2011 16:26:17 | Computer Name = SVETLANA | Source = Application Error | ID = 1001
Description = Fehlerhafter Speicherbereich -1753200436.

[ System Events ]
Error - 11.07.2011 14:28:23 | Computer Name = SVETLANA | Source = W32Time | ID = 39452701
Description = Der Zeitanbieter "NtpClient" wurde fur die Zeiterfassung von mehreren
Zeitquellen konfiguriert. Es ist jedoch Keine der Quellen verfugbar. Innerhalb der
nachsten 14 Minuten wird kein Versuch unternommen, eine Verbindung mit der Quelle
herzustellen. Der NtpClient verfugt uber keine Quelle mit genauer Zeit.

Error - 11.07.2011 14:29:51 | Computer Name = SVETLANA | Source = W32Time | ID = 39452689
Description = Zeitabieter "NtpClient": Beim DNS-Lookup fur den manuell konfigurierten
Peer "time.windows.com,0x1" ist ein Fehler aufgetreten. Der DNS-Lookup wird in 15
Minuten wiederholt. Fehler: Der Host war bei einem Socketvorgang nicht erreichbar.
(0x80072751)

Error - 11.07.2011 14:29:51 | Computer Name = SVETLANA | Source = W32Time | ID = 39452701
Description = Der Zeitanbieter "NtpClient" wurde fur die Zeiterfassung von mehreren
Zeitquellen konfiguriert. Es ist jedoch Keine der Quellen verfugbar. Innerhalb der
nachsten 14 Minuten wird kein Versuch unternommen, eine Verbindung mit der Quelle
herzustellen. Der NtpClient verfugt uber keine Quelle mit genauer Zeit.

Error - 11.07.2011 14:37:16 | Computer Name = SVETLANA | Source = Service Control Manager | ID = 7031
Description = Der Dienst "Norton AntiVirus" wurde unerwartet beendet. Dies ist bereits
1 Mal vorgekommen. Folgende Korrekturma?nahmen werden in 120000 Millisekunden durchgefuhrt:
Starten Sie den Dienst neu..

Error - 13.07.2011 14:47:19 | Computer Name = SVETLANA | Source = Service Control Manager | ID = 7016
Description = Der Dienst "BrSplService" hat einen ungultigen aktuellen Status gemeldet:
0

Error - 16.07.2011 03:38:36 | Computer Name = SVETLANA | Source = Service Control Manager | ID = 7016
Description = Der Dienst "BrSplService" hat einen ungultigen aktuellen Status gemeldet:
0

Error - 25.07.2011 11:23:00 | Computer Name = SVETLANA | Source = DCOM | ID = 10010
Description = Der Server "{5A5AA0AA-1DEB-4683-96B0-B43301E83971}" konnte innerhalb
des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.

Error - 27.07.2011 13:37:14 | Computer Name = SVETLANA | Source = atapi | ID = 262153
Description = Das Gerat \Device\Ide\IdePort0 hat innerhalb der Fehlerwartezeit nicht
geantwortet.

Error - 28.07.2011 11:23:56 | Computer Name = SVETLANA | Source = Service Control Manager | ID = 7016
Description = Der Dienst "BrSplService" hat einen ungultigen aktuellen Status gemeldet:
0

Error - 30.07.2011 16:00:33 | Computer Name = SVETLANA | Source = atapi | ID = 262153
Description = Das Gerat \Device\Ide\IdePort0 hat innerhalb der Fehlerwartezeit nicht
geantwortet.


< End of report >



2.) OTL.Txt:


OTL logfile created on: 30.07.2011 22:28:28 - Run 3
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Dokumente und Einstellungen\Sveta\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy

1,87 Gb Total Physical Memory | 0,66 Gb Available Physical Memory | 35,08% Memory free
4,54 Gb Paging File | 3,44 Gb Available in Paging File | 75,84% Paging File free
Paging file location(s): C:\pagefile.sys 2877 2877 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 94,22 Gb Total Space | 54,34 Gb Free Space | 57,68% Space Free | Partition Type: NTFS

Computer Name: SVETLANA | User Name: Sveta | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

< End of report >




Now, regarding aswMBR scan. I've just tried to run it two times, but the programm detect some problem and closes itself.


Regards,
Mimino
Hello Mimino

Delete aswMBR from your desktop and download aswMBR again, make sure your Anti-virus is turned off. If that doesn't work then run aswMBR in safe mode.


Please run aswMBR in safemode.

Please reboot your computer in SafeMode by doing the following:

* Restart your computer
* After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
* Instead of Windows loading as normal, a menu should appear
* Select the first option, to run Windows in Safe Mode.
* If you have trouble getting into Safe mode go here for more info.
======================
Please include in your next reply:
1. Any problem executing the instructions?
2.aswMBR log
Hello BlackPegasus!

I downloaded aswMBR again and run it in normal mode. Here is the logfile:


aswMBR version 0.9.8.978 Copyright© 2011 AVAST Software
Run date: 2011-07-31 18:48:15
—————————–
18:48:15.406 OS Version: Windows 5.1.2600 Service Pack 3
18:48:15.406 Number of processors: 2 586 0xE08
18:48:15.406 ComputerName: SVETLANA UserName: Sveta
18:48:26.812 Initialize success
18:48:44.843 AVAST engine defs: 11073000
18:49:06.609 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
18:49:06.609 Disk 0 Vendor: Hitachi_HTS541612J9AT00 SBDOA70H Size: 107196MB BusType: 3
18:49:08.671 Disk 0 MBR read successfully
18:49:08.671 Disk 0 MBR scan
18:49:08.765 Disk 0 unknown MBR code
18:49:08.781 Disk 0 scanning sectors +219528225
18:49:08.875 Disk 0 scanning C:\WINDOWS\system32\drivers
18:49:33.625 Service scanning
18:49:35.687 Modules scanning
18:49:43.984 Disk 0 trace - called modules:
18:49:44.000 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
18:49:44.000 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a61eab8]
18:49:44.000 3 CLASSPNP.SYS[f7637fd7] -> nt!IofCallDriver -> \Device\00000082[0x8a6219e8]
18:49:44.000 5 ACPI.sys[f75ad620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8a621d98]
18:49:44.421 AVAST engine scan C:\WINDOWS
18:50:14.968 AVAST engine scan C:\WINDOWS\system32
18:53:29.343 AVAST engine scan C:\WINDOWS\system32\drivers
18:53:47.859 AVAST engine scan C:\Dokumente und Einstellungen\Sveta
19:23:19.343 AVAST engine scan C:\Dokumente und Einstellungen\All Users
19:24:35.828 Scan finished successfully
19:44:46.968 Disk 0 MBR has been saved successfully to "C:\Dokumente und Einstellungen\Sveta\Desktop\MBR.dat"
19:44:47.015 The log file has been saved successfully to "C:\Dokumente und Einstellungen\Sveta\Desktop\aswMBR.txt"

Hello Mimino

Please go to one of the below sites to scan the following files:
Virus Total
jotti.org
Kaspersky Virus File Scanner


click on Browse, and upload the following file for analysis:

C:\WINDOWS\is-Q6GUP.exe
C:\WINDOWS\is-Q6GUP.msg
C:\WINDOWS\is-Q6GUP.lst


Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.
If it says already scanned – click "reanalyze now"
Please post the results in your next reply.
=======================
NEXT

type the following text into the run box

appwiz.cpl

This will open your Programs And Features A list of installed programs will populate

Remove the following programs:

Bandoo
iLivid
Windows iLivid Toolbar

=======================
NEXT

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    PRC - C:\Programme\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Bandoo Media, inc)
    FF - prefs.js..browser.search.defaultenginename: "Search Results"
    FF - prefs.js..browser.search.order.1: "Search Results"
    FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/406"
    FF - prefs.js..keyword.URL: "http://dts.search-results.com/sr?src=ffb&appid=102&systemid=406&q="
    [2011.07.26 17:47:18 | 000,002,501 | —- | M] () – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\Mozilla\Firefox\Profiles\mhq82cpm.default\searchplugins\SearchResults.xml
    File not found (No name found) –
    O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Programme\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
    O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Programme\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Bandoo Media, inc)
    O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Programme\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
    O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - File not found
    O4 - HKLM..\Run: [] File not found
    O4 - HKLM..\Run: [DATAMNGR] C:\Programme\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Bandoo Media, inc)
    O20 - AppInit_DLLs: (C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll) - C:\Programme\Windows iLivid Toolbar\Datamngr\datamngr.dll (Bandoo Media, inc)
    O20 - AppInit_DLLs: (C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll) - C:\Programme\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Bandoo Media, inc)
    O33 - MountPoints2\{26e7d15c-270e-11df-9a52-0013773197b5}\Shell - "" = AutoRun
    O33 - MountPoints2\{26e7d15c-270e-11df-9a52-0013773197b5}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{26e7d15c-270e-11df-9a52-0013773197b5}\Shell\AutoRun\command - "" = E:\AutoRun.exe
    O33 - MountPoints2\{26e7d160-270e-11df-9a52-0013773197b5}\Shell - "" = AutoRun
    O33 - MountPoints2\{26e7d160-270e-11df-9a52-0013773197b5}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{26e7d160-270e-11df-9a52-0013773197b5}\Shell\AutoRun\command - "" = E:\AutoRun.exe
    O33 - MountPoints2\{35bc88f8-700a-11db-a6b2-0013773197b5}\Shell - "" = AutoRun
    O33 - MountPoints2\{35bc88f8-700a-11db-a6b2-0013773197b5}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{35bc88f8-700a-11db-a6b2-0013773197b5}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
    O33 - MountPoints2\{432b284c-279c-11df-9a58-0013773197b5}\Shell - "" = AutoRun
    O33 - MountPoints2\{432b284c-279c-11df-9a58-0013773197b5}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{432b284c-279c-11df-9a58-0013773197b5}\Shell\AutoRun\command - "" = E:\AutoRun.exe
    [2011.07.26 19:00:12 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\searchquband
    [2011.07.26 18:47:24 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\PriceGong
    [2011.07.26 17:52:11 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Bandoo
    [2011.07.26 17:51:58 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\Sveta\Lokale Einstellungen\Anwendungsdaten\Ilivid Player
    [2011.07.26 17:51:55 | 000,000,000 | —D | C] – C:\Programme\Bandoo
    [2011.07.26 17:48:50 | 000,000,000 | -H-D | C] – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{9CD61942-8DA1-4781-925C-4FE1471E0820}
    [2011.07.26 17:48:28 | 000,000,000 | —D | C] – C:\Programme\iLivid
    [2011.07.26 17:47:38 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\searchqutoolbar
    [2011.07.26 17:47:18 | 000,000,000 | —D | C] – C:\Programme\Windows iLivid Toolbar
    [2011.07.26 17:33:57 | 000,000,000 | —D | C] – C:\Programme\Free Offers from Freeze.com
    [2011.07.26 17:51:50 | 001,524,112 | —- | C] () – C:\WINDOWS\System32\bandoolmx.dll
    
    
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [createrestorepoint]
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
===========================
Next

Download and Run ComboFix
  • Please download ComboFix from one of the following links.

    Link 1.

    Link 2.

    **IMPORTANT !!! Save ComboFix.exe to your Desktop**
  • Please disable any Antivirus or Firewall you have active, as shown in this topic. Please close all open application windows.
  • Double click on ComboFix.exe & follow the prompts
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console
[external image: Posted Image]
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
  • When finished, it shall produce a log for you. Please include the contents of C:\ComboFix.txt in your next reply
A word of warning: Neither I nor sUBs are responsible for any damage you may cause to your machine by running ComboFix on your own. This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper

===========================
Please include in your next reply:
1. Any problem executing the instructions?
2. OTL log
3. Combofix log
4. virus results
How is the computer behaving?
Hello BlackPegasus! I just want to say - this step will take me some more time. I'll try to come to it tomorrow. Sorry for offtop. Regards, Mimino
Hello BlackPegasus!

Sorry for hold-up!

As you instructed, I firstly analysed those three files by Kaspersky-antivirus - no malicious stuff was identified.

Then I run OTL; here is the log-file:


All processes killed
========== OTL ==========
No active process named datamngrUI.exe was found!
Prefs.js: "Search Results" removed from browser.search.defaultenginename
Prefs.js: "Search Results" removed from browser.search.order.1
Prefs.js: "http://www.searchqu.com/406" removed from browser.startup.homepage
Prefs.js: "http://dts.search-results.com/sr?src=ffb&appid=102&systemid=406&q=" removed from keyword.URL
C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\Mozilla\Firefox\Profiles\mhq82cpm.default\searchplugins\SearchResults.xml moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{99079a25-328f-4bd4-be04-00955acaa0a7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}\ deleted successfully.
File C:\Programme\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ not found.
File C:\Programme\Windows iLivid Toolbar\Datamngr\IEBHO.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{99079a25-328f-4bd4-be04-00955acaa0a7} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}\ not found.
File C:\Programme\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{3041D03E-FD4B-44E0-B742-2D9B88305F98} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3041D03E-FD4B-44E0-B742-2D9B88305F98}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\DATAMNGR not found.
File C:\Programme\Windows iLivid Toolbar\Datamngr\datamngrUI.exe not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll deleted successfully.
C:\Programme\Windows iLivid Toolbar\Datamngr\datamngr.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll deleted successfully.
File C:\Programme\Windows iLivid Toolbar\Datamngr\IEBHO.dll not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{26e7d15c-270e-11df-9a52-0013773197b5}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{26e7d15c-270e-11df-9a52-0013773197b5}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{26e7d15c-270e-11df-9a52-0013773197b5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{26e7d15c-270e-11df-9a52-0013773197b5}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{26e7d15c-270e-11df-9a52-0013773197b5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{26e7d15c-270e-11df-9a52-0013773197b5}\ not found.
File E:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{26e7d160-270e-11df-9a52-0013773197b5}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{26e7d160-270e-11df-9a52-0013773197b5}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{26e7d160-270e-11df-9a52-0013773197b5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{26e7d160-270e-11df-9a52-0013773197b5}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{26e7d160-270e-11df-9a52-0013773197b5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{26e7d160-270e-11df-9a52-0013773197b5}\ not found.
File E:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{35bc88f8-700a-11db-a6b2-0013773197b5}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{35bc88f8-700a-11db-a6b2-0013773197b5}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{35bc88f8-700a-11db-a6b2-0013773197b5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{35bc88f8-700a-11db-a6b2-0013773197b5}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{35bc88f8-700a-11db-a6b2-0013773197b5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{35bc88f8-700a-11db-a6b2-0013773197b5}\ not found.
File E:\LaunchU3.exe -a not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{432b284c-279c-11df-9a58-0013773197b5}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{432b284c-279c-11df-9a58-0013773197b5}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{432b284c-279c-11df-9a58-0013773197b5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{432b284c-279c-11df-9a58-0013773197b5}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{432b284c-279c-11df-9a58-0013773197b5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{432b284c-279c-11df-9a58-0013773197b5}\ not found.
File E:\AutoRun.exe not found.
C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\searchquband folder moved successfully.
C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\PriceGong folder moved successfully.
Folder C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Bandoo\ not found.
C:\Dokumente und Einstellungen\Sveta\Lokale Einstellungen\Anwendungsdaten\Ilivid Player folder moved successfully.
C:\Programme\Bandoo\Plugins\MSN\Resources\HTML folder moved successfully.
C:\Programme\Bandoo\Plugins\MSN\Resources folder moved successfully.
C:\Programme\Bandoo\Plugins\MSN folder moved successfully.
C:\Programme\Bandoo\Plugins folder moved successfully.
C:\Programme\Bandoo folder moved successfully.
Folder C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{9CD61942-8DA1-4781-925C-4FE1471E0820}\ not found.
Folder C:\Programme\iLivid\ not found.
Folder C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\searchqutoolbar\ not found.
C:\Programme\Windows iLivid Toolbar\Datamngr folder moved successfully.
C:\Programme\Windows iLivid Toolbar folder moved successfully.
C:\Programme\Free Offers from Freeze.com folder moved successfully.
File C:\WINDOWS\System32\bandoolmx.dll not found.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
========== COMMANDS ==========
Restore point Set: OTL Restore Point (0)

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67561 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 49219 bytes

User: Sveta
->Temp folder emptied: 650860572 bytes
->Temporary Internet Files folder emptied: 2484822 bytes
->Java cache emptied: 240255 bytes
->FireFox cache emptied: 53443059 bytes
->Apple Safari cache emptied: 5325824 bytes
->Opera cache emptied: 15087458 bytes
->Flash cache emptied: 78074 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 16639 bytes
RecycleBin emptied: 1666704206 bytes

Total Files Cleaned = 2.283,00 mb


OTL by OldTimer - Version 3.2.26.1 log created on 08022011_150236

Files\Folders moved on Reboot…
File\Folder C:\Dokumente und Einstellungen\Sveta\Lokale Einstellungen\Temp\Perflib_Perfdata_48ac.dat not found!
File\Folder C:\WINDOWS\temp\Perflib_Perfdata_130.dat not found!

Registry entries deleted on Reboot…


And finally I checked my PC with ComboFix; here is the log-file:

ComboFix 11-08-05.01 - Sveta 05.08.2011 12:39:17.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1251.7.1031.18.1918.1259 [GMT 2:00]
Running from: c:\dokumente und einstellungen\Sveta\Desktop\ComboFix.exe
AV: Norton AntiVirus *Enabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\dokumente und einstellungen\Sveta\WINDOWS
c:\windows\isRS-000.tmp
c:\windows\system32\pthreadVC.dll
c:\windows\system32\rnaph.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_NPF
.
.
((((((((((((((((((((((((( Files Created from 2011-07-05 to 2011-08-05 )))))))))))))))))))))))))))))))
.
.
2011-08-02 13:02 . 2011-08-02 13:02 ——– d—–w- C:\_OTL
2011-07-27 18:48 . 2011-07-27 18:48 ——– d—–w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\DivX
2011-07-26 20:00 . 2011-07-26 20:01 ——– d—–w- c:\dokumente und einstellungen\Sveta\Anwendungsdaten\vlc
2011-07-26 19:57 . 2011-07-26 19:57 ——– d—–w- c:\programme\VideoLAN
2011-07-26 17:00 . 2011-07-26 17:00 ——– d—–w- c:\dokumente und einstellungen\Sveta\AppData
2011-07-26 16:47 . 2011-07-26 16:47 ——– d—–w- c:\dokumente und einstellungen\Sveta\Anwendungsdaten\RegistryKeys
2011-07-26 16:46 . 2011-07-26 16:46 ——– d—–w- c:\dokumente und einstellungen\Sveta\Lokale Einstellungen\Anwendungsdaten\PackageAware
2011-07-26 16:46 . 2011-08-02 12:58 ——– d-sh–w- c:\windows\system32\AI_RecycleBin
2011-07-26 15:47 . 2011-07-26 16:49 ——– d—–w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\boost_interprocess
2011-07-26 15:33 . 2011-07-26 16:47 ——– d—–w- c:\programme\Yahoo!
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-06 17:52 . 2010-09-30 17:28 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-06 17:52 . 2010-09-30 17:28 22712 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-06-29 16:36 . 2011-06-11 08:21 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-06 11:35 . 2006-10-10 02:52 1859072 —-a-w- c:\windows\system32\win32k.sys
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\programme\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\programme\mozilla firefox\plugins\ssldivx.dll
2011-06-22 19:45 . 2011-05-07 19:11 142296 —-a-w- c:\programme\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPLJ Config"="c:\programme\Hewlett-Packard\hp LaserJet 1010 Series\SetConfig.exe" [2003-03-31 28672]
"Adobe Reader Speed Launcher"="c:\programme\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
"Adobe ARM"="c:\programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"ArcSoft Connection Service"="c:\programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-27 207424]
"StatusClient"="c:\programme\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe" [2002-12-16 36864]
"TomcatStartup"="c:\programme\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe" [2003-03-31 155648]
"EEventManager"="c:\progra~1\EPSONS~1\EVENTM~1\EEventManager.exe" [2008-12-04 665424]
"QuickTime Task"="c:\programme\QuickTime\QTTask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\programme\iTunes\iTunesHelper.exe" [2011-03-07 421160]
"SunJavaUpdateSched"="c:\programme\Gemeinsame Dateien\Java\Java Update\jusched.exe" [2011-04-08 254696]
"Malwarebytes' Anti-Malware"="c:\programme\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-06 449584]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\GEMEIN~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 39264]
.
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenu^Programme^Autostart^HP Digital Imaging Monitor.lnk]
path=c:\dokumente und einstellungen\All Users\Startmenu\Programme\Autostart\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^Sveta^Startmenu^Programme^Autostart^BBC iPlayer Desktop.lnk]
path=c:\dokumente und einstellungen\Sveta\Startmenu\Programme\Autostart\BBC iPlayer Desktop.lnk
backup=c:\windows\pss\BBC iPlayer Desktop.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-30 04:59 937920 —-a-r- c:\programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2005-06-06 21:46 57344 —-a-w- c:\programme\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-06-08 04:02 37296 —-a-w- c:\programme\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
2006-06-29 20:32 89541 —-a-w- c:\windows\AGRSMMSG.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-04 01:43 69632 —-a-w- c:\windows\Alcmtr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
2006-01-02 16:41 45056 —-a-w- c:\programme\ATI Technologies\ATI.ACE\CLI.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVStation Premium 3.75]
2006-07-14 16:10 159744 —-a-w- c:\programme\Samsung\AVStation Premium 3.75\AVSAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BatteryManager]
2006-04-25 12:05 2764800 —-a-w- c:\programme\Samsung\Samsung Battery Manager\BatteryManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 02:22 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DisplayManager]
2006-09-18 15:36 413696 —-a-w- c:\programme\Samsung\DisplayManager\DisplayManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMHotKey]
2005-11-23 09:18 356352 —-a-w- c:\programme\Samsung\DisplayManager\DMLoader.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EDS]
2006-03-28 11:27 634880 —-a-w- c:\programme\Samsung\Samsung EDS\EDSAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
2005-08-05 11:34 64512 —-a-w- c:\windows\ehome\ehtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus C82 Series]
2003-10-15 02:02 99840 —-a-w- c:\windows\system32\spool\drivers\w32x86\3\E_S0HIC1.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus DX4000 Series]
2006-09-21 02:01 139264 —-a-w- c:\windows\system32\spool\drivers\w32x86\3\E_FATIBEE.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2011-06-05 19:17 136176 —-atw- c:\dokumente und einstellungen\Sveta\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2005-05-11 21:12 49152 —-a-w- c:\programme\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MagicKeyboard]
2006-05-17 20:24 151552 —-a-w- c:\programme\Samsung\MagicKBD\PreMKbd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 02:22 1695232 —-a-w- c:\programme\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 15:38 421888 —-a-w- c:\programme\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
1999-03-14 22:00 37376 —-a-w- c:\programme\Microsoft Money\System\REMINDER.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RestoreIT!]
2004-09-23 17:27 114688 —-a-w- c:\programme\Phoenix Technologies Ltd\RecoverPro_XP\vbptask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2006-04-05 00:44 16120832 —-a-w- c:\windows\RTHDCPL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StatusClient]
2002-12-16 15:51 36864 —-a-w- c:\programme\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2005-12-07 21:44 761947 —-a-w- c:\programme\Synaptics\SynTP\SynTPEnh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomcatStartup]
2003-03-31 18:28 155648 —-a-w- c:\programme\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Programme\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programme\\Skype\\Phone\\Skype.exe"=
"c:\\Programme\\Hewlett-Packard\\Toolbox2.0\\Javasoft\\JRE\\1.3.1\\bin\\javaw.exe"=
"c:\\Programme\\NewSoft\\Presto! PageManager 6\\NetGroup.exe"=
"c:\\Programme\\Java\\jre6\\bin\\java.exe"=
"c:\\Dokumente und Einstellungen\\Sveta\\Lokale Einstellungen\\Anwendungsdaten\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Programme\\Opera\\opera.exe"=
"c:\\Programme\\Epson Software\\Event Manager\\EEventManager.exe"=
"c:\\Programme\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\Programme\\Bonjour\\mDNSResponder.exe"=
"c:\\Programme\\iTunes\\iTunes.exe"=
.
R0 RITCPT;RITCPT;c:\windows\system32\drivers\RITCPT.SYS [09.10.2006 20:40 43512]
R0 VVBackd5;VVBackd5;c:\windows\system32\drivers\VVBackd5.sys [14.01.2007 03:40 179831]
R2 DOSMEMIO;MEMIO;c:\windows\system32\MEMIO.SYS [09.10.2006 20:31 4300]
R2 FBAPI;FBAPI;c:\windows\system32\drivers\FBAPI.sys [09.10.2006 20:40 5088]
R2 MBAMService;MBAMService;c:\programme\Malwarebytes' Anti-Malware\mbamservice.exe [30.09.2010 19:28 366640]
R2 Norton PC Checkup Application Launcher;Norton PC Checkup Application Launcher;c:\programme\Norton PC Checkup\Engine\2.0.6.11\SymcPCCULaunchSvc.exe [26.09.2010 13:56 120248]
R2 PCCUJobMgr;Common Client Job Manager Service;c:\programme\Norton PC Checkup\Engine\2.0.6.11\ccSvcHst.exe [26.09.2010 13:56 126392]
R2 SNM WLAN Service;SNM WLAN Service;c:\programme\Samsung\Samsung Network Manager\SNMWLANService.exe [28.05.2005 08:35 36864]
R3 DNSeFilter;DNSeFilter;c:\windows\system32\drivers\SamsungEDS.SYS [29.03.2006 12:59 27648]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [30.09.2010 19:28 22712]
R3 SSB2413;SSB2413 Wireless Network Adapter Service;c:\windows\system32\drivers\SSB2413.sys [09.10.2006 20:36 470112]
S2 gupdate1c9fd69e5bf5f8c;Google Update Service (gupdate1c9fd69e5bf5f8c);c:\programme\Google\Update\GoogleUpdate.exe [05.07.2009 14:12 133104]
S3 BALU;ModiTel;c:\windows\system32\drivers\balu.sys [15.07.2005 12:47 10240]
S3 gupdatem;Google Update-Dienst (gupdatem);c:\programme\Google\Update\GoogleUpdate.exe [05.07.2009 14:12 133104]
S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys –> c:\windows\system32\DRIVERS\ewusbdev.sys [?]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\programme\McAfee Security Scan\2.0.181\McCHSvc.exe [15.01.2010 14:49 227232]
S3 PAC207;Trust WB-1400T Webcam;c:\windows\system32\DRIVERS\pfc027.sys –> c:\windows\system32\DRIVERS\pfc027.sys [?]
S3 SUEPD;SUE NDIS Protocol Driver;c:\windows\system32\drivers\SUE_PD.sys [10.06.2008 12:32 19840]
.
Contents of the 'Scheduled Tasks' folder
.
2011-08-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programme\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
2011-08-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programme\Google\Update\GoogleUpdate.exe [2009-07-05 12:12]
.
2011-08-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programme\Google\Update\GoogleUpdate.exe [2009-07-05 12:12]
.
2011-07-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3771985245-72322722-229232620-1006Core.job
- c:\dokumente und einstellungen\Sveta\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe [2011-06-26 19:17]
.
2011-08-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3771985245-72322722-229232620-1006UA.job
- c:\dokumente und einstellungen\Sveta\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe [2011-06-26 19:17]
.
2011-08-04 c:\windows\Tasks\User_Feed_Synchronization-{17A5E491-0DBB-40A1-85C3-BC4969F1A904}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://de.search.yahoo.com/?fr=w3i&type=W3i_SP,204,0_0,StartPage,20110731,16992,0,6,0
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mWindow Title = Microsoft Internet Explorer
uInternet Settings,ProxyOverride = ;*.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{F1BE9A58-7EA5-4B3B-87A6-7FE19D946D05}: DhcpNameServer = 192.168.0.1
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://axis.udm.net/activex/AMC.cab
FF - ProfilePath - c:\dokumente und einstellungen\Sveta\Anwendungsdaten\Mozilla\Firefox\Profiles\mhq82cpm.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - (no file)
HKCU-Run-Startw3i - c:\programme\PC Speed Maximizer\Startw3i.exe
HKLM-Run-EPSON Stylus Photo R240 Series - c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAHE.EXE
SafeBoot-klmdb.sys
MSConfigStartUp-ccApp - c:\programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe
MSConfigStartUp-RealTray - c:\programme\Real\RealPlayer\RealPlay.exe
MSConfigStartUp-SunJavaUpdateSched - c:\programme\Java\jre6\bin\jusched.exe
MSConfigStartUp-swg - c:\programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
MSConfigStartUp-updateMgr - c:\programme\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
AddRemove-{79221CA7-A39A-4AE5-A558-B5D928393FC4}_is1 - c:\programme\File Extractor\unins000.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-08-05 12:48
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PCCUJobMgr]
"ImagePath"="\"c:\programme\Norton PC Checkup\Engine\2.0.6.11\ccSvcHst.exe\" /s \"PCCUJobMgr\" /m \"c:\programme\Norton PC Checkup\Engine\2.0.6.11\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ђ–Ђ|яяяяА•Ђ|щ•6~*]
"7040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(624)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(3396)
c:\progra~1\WINDOW~3\wmpband.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\brss01a.exe
c:\windows\system32\Ati2evxx.exe
c:\programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACService.exe
c:\programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\programme\Bonjour\mDNSResponder.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\programme\Java\jre6\bin\jqs.exe
c:\programme\Gemeinsame Dateien\LightScribe\LSSrvc.exe
c:\windows\system32\HPZipm12.exe
c:\windows\System32\PAStiSvc.exe
c:\programme\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
c:\programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ArcCon.ac
c:\programme\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe
c:\programme\iPod\bin\iPodService.exe
c:\windows\system32\dwwin.exe
.
**************************************************************************
.
Completion time: 2011-08-05 12:55:58 - machine was rebooted
ComboFix-quarantined-files.txt 2011-08-05 10:55
.
Pre-Run: 14 Verzeichnis(se), 60.549.222.400 Bytes frei
Post-Run: 18 Verzeichnis(se), 60.846.387.200 Bytes frei
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
.
- - End Of File - - EE01AE2376D734F4C9A511A2E7C4C1DD



No problem with redirection so far.

Thanks a lot!
Mimino

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI