This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] HIjackThis logfile

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm running win XP prof, SP2 with all patches.
virusscanner ist avast
firewall: comodo

since yesterday I noticed, that is comodo noticed that the process smss.exe is strangely active, trying to get to the internet, using port 3071.
defence+ tells me, it doesnt recognize the process. on searching, i found several instances of smss.exe.
when shutting down the pc, I get a runtime error.

i ran spybot and it didnt find anything apart from some tracking cookies.

now i am not sure whether this is really malware or just some leftover from an uninstall, or something like that.
I really would appreciate help.



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:52:34, on 18.02.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programme\TuneUp Utilities 2004\WinStylerThemeSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.exe
C:\Programme\Alwil Software\Avast4\aswUpdSv.exe
C:\Programme\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Config\smss.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\Cobian Backup 8\cbInterface.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Programme\Comodo\Firewall\cfp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Wallperizer\Wallperizer.exe
C:\Programme\a-squared Free\a2service.exe
C:\Programme\Comodo\Firewall\cmdagent.exe
C:\Programme\Cobian Backup 8\cbService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Programme\Alwil Software\Avast4\ashMaiSv.exe
C:\Programme\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\Mozilla Firefox\firefox.exe
D:\Scribble Papers\ScPapers.exe
C:\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Config\smss.exe
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Cobian Backup 8 interface] "C:\Programme\Cobian Backup 8\cbInterface.exe" -service
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Programme\Comodo\Firewall\cfp.exe" -s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Wallperizer.lnk = C:\Wallperizer\Wallperizer.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1193570037906
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1195995401562
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Programme\a-squared Free\a2service.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programme\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programme\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programme\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programme\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - COMODO - C:\Programme\Comodo\Firewall\cmdagent.exe
O23 - Service: Cobian Backup 8 Service (CobBMService) - Luis Cobian - C:\Programme\Cobian Backup 8\cbService.exe
O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Programme\SiSoftware\SiSoftware Sandra Lite XII.SP1\Win32\RpcDataSrv.exe
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Programme\SiSoftware\SiSoftware Sandra Lite XII.SP1\RpcSandraSrv.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Programme\TuneUp Utilities 2004\WinStylerThemeSvc.exe

–
End of file - 6167 bytes
Hi Severus,

Please open this page in your browser:
http://www.bleepingcomputer.com/submit-mal….php?channel=32

Please fill in the link to topic field with a link to this topic
Copy/paste the following into the Browse to the file you want to submit field:

C:\WINDOWS\Config\smss.exe

Then press Send File, this will upload the file for analysis


Next, download Deckard's System Scanner (DSS) to your Desktop (right-click the link, select Save Target As…, select your Desktop and press Save)
  • Close all applications and windows.
  • Double-click on dss.exe to run it, and follow the prompts.
  • When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt<-this one will be minimized
  • Make sure Format->Word Wrap is unchecked
  • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt and extra.txt in your reply


Once complete, please post both DSS logs, you won't need to produce a new HijackThis log as DSS produces one for you.
Thank You very much for helping.
I submitted the file and here are the dss files as requested.

main.txt:

Deckard's System Scanner v20071014.68
Run by [removed] on 2008-02-20 11:41:06
Computer is in Normal Mode.
——————————————————————————–

– System Restore ————————————————————–

Successfully created a Deckard's System Scanner Restore Point.


– Last 5 Restore Point(s) –
11: 2008-02-20 10:41:13 UTC - RP174 - Deckard's System Scanner Restore Point
10: 2008-02-19 22:15:27 UTC - RP173 - Systemprüfpunkt
9: 2008-02-18 19:48:06 UTC - RP172 - Systemprüfpunkt
8: 2008-02-17 14:28:35 UTC - RP171 - Systemprüfpunkt
7: 2008-02-16 14:20:58 UTC - RP170 - Systemprüfpunkt


– First Restore Point –
1: 2008-02-08 10:31:41 UTC - RP164 - Software Distribution Service 3.0


Backed up registry hives.
Performed disk cleanup.



– HijackThis (run as Severus.exe) ———————————————

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:42:13, on 20.02.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programme\TuneUp Utilities 2004\WinStylerThemeSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Programme\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\Explorer.exe
C:\Programme\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Config\smss.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\Cobian Backup 8\cbInterface.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Programme\Comodo\Firewall\cfp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Wallperizer\Wallperizer.exe
C:\Programme\a-squared Free\a2service.exe
C:\Programme\Comodo\Firewall\cmdagent.exe
C:\Programme\Cobian Backup 8\cbService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Programme\Alwil Software\Avast4\ashMaiSv.exe
C:\Programme\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\Dokumente und Einstellungen\Severus\Desktop\dss.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\TRENDM~1\HIJACK~1\Severus.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Config\smss.exe
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Cobian Backup 8 interface] "C:\Programme\Cobian Backup 8\cbInterface.exe" -service
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Programme\Comodo\Firewall\cfp.exe" -s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Wallperizer.lnk = C:\Wallperizer\Wallperizer.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1193570037906
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1195995401562
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Programme\a-squared Free\a2service.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programme\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programme\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programme\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programme\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - COMODO - C:\Programme\Comodo\Firewall\cmdagent.exe
O23 - Service: Cobian Backup 8 Service (CobBMService) - Luis Cobian - C:\Programme\Cobian Backup 8\cbService.exe
O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Programme\SiSoftware\SiSoftware Sandra Lite XII.SP1\Win32\RpcDataSrv.exe
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Programme\SiSoftware\SiSoftware Sandra Lite XII.SP1\RpcSandraSrv.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Programme\TuneUp Utilities 2004\WinStylerThemeSvc.exe

–
End of file - 6140 bytes

– File Associations ———————————————————–

.bat - batfile - DefaultIcon - C:\WINDOWS\Icons\genesis2\Genesis 2.icl,48
.cmd - cmdfile - DefaultIcon - C:\WINDOWS\Icons\genesis2\Genesis 2.icl,49
.ini - inifile - DefaultIcon - C:\WINDOWS\Icons\genesis2\Genesis 2.icl,45
.txt - txtfile - DefaultIcon - C:\WINDOWS\Icons\genesis2\Genesis 2.icl,41


– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————

R0 vax347b - c:\windows\system32\drivers\vax347b.sys
R0 vax347s - c:\windows\system32\drivers\vax347s.sys
R2 atksgt - c:\windows\system32\drivers\atksgt.sys
R2 lirsgt - c:\windows\system32\drivers\lirsgt.sys

S3 ASFWHide - c:\dokume~1\severus\lokale~1\temp\asfwhide (file missing)
S3 LUsbKbd (Logitech SetPoint USB Filter Driver) - c:\windows\system32\drivers\lusbkbd.sys (file missing)


– Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ——————–

R2 CobBMService (Cobian Backup 8 Service) - c:\programme\cobian backup 8\cbservice.exe
Hi Severus,

Please open Start->Control Panel->Add/Remove Programs, look down the list for these items and remove them:

Java 2 Runtime Environment, SE v1.4.2_01
JavaT 6 Update 3

These are out of date and now a security risk, you can get the latest update (version 6 update 4) from here

You have eMule, a P2P file sharing program installed on your computer. This program does not come bundled with malware as some similar programs do, but peer-to-peer file sharing networks are one of the biggest sources of malware we see. Anything downloaded from them cannot be trusted to be clean, because even if the file appears to be what it claims to be, it can have malware embedded in it.
I recommend you remove it, but of course the choice is yours.
You can remove eMule via Add/Remove Programs.

————————————————————————

Then, open HijackThis, choose Do a system scan only and place a checkmark next to the following lines:

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Config\smss.exe

Then close all open windows apart from HijackThis, press Fix checked, OK the prompt and close HijackThis.

————————————————————————

Now, reboot your computer

Make hidden/system files and folders visible:
Click Start -> My Computer
Select the Tools menu, click Folder Options and select the View tab
Under the Hidden files and folders heading SELECT Show hidden files and folders
UNCHECK the Hide extensions for known file types option
UNCHECK the Hide protected operating system files (recommended) option
Click Yes to confirm and press OK

Use Windows Explorer (right-click Start, select Explore) to find and delete the following file:

C:\WINDOWS\Config\smss.exe

If you have trouble finding or deleting it, please let me know in your next response.
There is a legitimate file with the same name located in the C:\Windows\System32 folder - please do not delete this one.

————————————————————————

Please upload some files for scanning:
Open http://virusscan.jotti.org/
Copy/paste this file and path into the white box at the top:

C:\HTGD0005.exe

Press Submit - this will submit the file for testing.
Please wait for all the scanners to finish then copy and paste the results in your next response.

Then, repeat the process for this file:

C:\HTGD0003.exe


Note: If Jotti is busy, you can use VirusTotal instead.

————————————————————————

Once complete, please post the Jotti results for those two files and a new HijackThis log.
i have not yet installed the new java files, just deleted the old.

the files from jotti and virus total:

File: HTGD0005.exe Status:
OK
MD5: 3da3042cc76c49034322fedabd9a5ae7 Packers detected:
-
Bit9 reports: File not found

A-Squared
Found nothing
AntiVir
Found nothing
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found nothing
ClamAV
Found nothing
CPsecure
Found nothing
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
F-Secure Anti-Virus
Found nothing
Fortinet
Found nothing
Ikarus
Found nothing
Kaspersky Anti-Virus
Found nothing
NOD32
Found nothing
Norman Virus Control
Found nothing
Panda Antivirus
Found nothing
Rising Antivirus
Found nothing
Sophos Antivirus
Found nothing
VirusBuster
Found nothing
VBA32
Found nothing
——————————————–
Datei HTGD0003.exe empfangen 2008.02.20 13:39:03 (CET)
Status: Beendet

Ergebnis: 0/32 (0%)




Antivirus
Version
letzte aktualisierung
Ergebnis
AhnLab-V3
2008.2.20.0
2008.02.20
-
AntiVir
7.6.0.67
2008.02.20
-
Authentium
4.93.8
2008.02.20
-
Avast
4.7.1098.0
2008.02.20
-
AVG
7.5.0.516
2008.02.20
-
BitDefender
7.2
2008.02.20
-
CAT-QuickHeal
9.50
2008.02.18
-
ClamAV
0.92.1
2008.02.20
-
DrWeb
4.44.0.09170
2008.02.20
-
eSafe
7.0.15.0
2008.02.17
-
eTrust-Vet
31.3.5549
2008.02.20
-
Ewido
4.0
2008.02.19
-
FileAdvisor
1
2008.02.20
-
Fortinet
3.14.0.0
2008.02.19
-
F-Prot
4.4.2.54
2008.02.19
-
F-Secure
6.70.13260.0
2008.02.20
-
Ikarus
T3.1.1.20
2008.02.20
-
Kaspersky
7.0.0.125
2008.02.20
-
McAfee
5233
2008.02.20
-
Microsoft
1.3204
2008.02.20
-
NOD32v2
2887
2008.02.20
-
Norman
5.80.02
2008.02.19
-
Panda
9.0.0.4
2008.02.20
-
Prevx1
V2
2008.02.20
-
Rising
20.32.22.00
2008.02.20
-
Sophos
4.26.0
2008.02.20
-
Sunbelt
3.0.884.0
2008.02.19
-
Symantec
10
2008.02.20
-
TheHacker
[removed]
2008.02.19
-
VBA32
[removed]
2008.02.17
-
VirusBuster
4.3.26:9
2008.02.19
-
Webwasher-Gateway
6.6.2
2008.02.20
-

weitere Informationen
File size: 40960 bytes
MD5: 31fcd9a08851420f8dbada4bf08ae4ed
SHA1: 106e5b03c071fadfe00718850f6862487d49be68
PEiD: Armadillo v1.71
——————————————————————


and here is the hijackthis file:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:51:43, on 20.02.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programme\TuneUp Utilities 2004\WinStylerThemeSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\Alwil Software\Avast4\aswUpdSv.exe
C:\Programme\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\Cobian Backup 8\cbInterface.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Programme\Comodo\Firewall\cfp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Wallperizer\Wallperizer.exe
C:\Programme\a-squared Free\a2service.exe
C:\Programme\Comodo\Firewall\cmdagent.exe
C:\Programme\Cobian Backup 8\cbService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Programme\Alwil Software\Avast4\ashMaiSv.exe
C:\Programme\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Cobian Backup 8 interface] "C:\Programme\Cobian Backup 8\cbInterface.exe" -service
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Programme\Comodo\Firewall\cfp.exe" -s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Wallperizer.lnk = C:\Wallperizer\Wallperizer.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1193570037906
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1195995401562
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Programme\a-squared Free\a2service.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programme\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programme\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programme\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programme\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - COMODO - C:\Programme\Comodo\Firewall\cmdagent.exe
O23 - Service: Cobian Backup 8 Service (CobBMService) - Luis Cobian - C:\Programme\Cobian Backup 8\cbService.exe
O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Programme\SiSoftware\SiSoftware Sandra Lite XII.SP1\Win32\RpcDataSrv.exe
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Programme\SiSoftware\SiSoftware Sandra Lite XII.SP1\RpcSandraSrv.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Programme\TuneUp Utilities 2004\WinStylerThemeSvc.exe

–
End of file - 5637 bytes

thanks again for helping.
Hi Severus,

That all looks good :)


Please do an online scan with Kaspersky:
Open Kaspersky Online Scanner in Internet Explorer using this link:
http://www.kaspersky.com/kos/eng/partner/d…kavwebscan.html
  • Click Accept and the web scanner will begin to load
  • If a yellow warning bar appears at the top of the browser, click it and choose Install ActiveX Control
  • You will be prompted to install an ActiveX component from Kaspersky, click Install
  • If you are prompted about another ActiveX control called Kaspersky Online Scanner GUI part then allow it to be installed also.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT and then Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • The program will start to scan your system.
  • Once the scan is complete, click on the Save as Text button and save the file to your desktop
Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the license, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license is accepted, reset to 100%.


Once complete, please post the Kaspersky report and a new HijackThis log. Also, let me know how your machine is running.
It took some time, but here is the kaspersky log. a bit long though, sorry ;-).
my pc is running fine, not slowing down or anything. and I dont get the alerts that smss.exe wants to access files. no weird popups or stuff either.
as for ths viruses kaspersky found, all the stuff seems to sit in ages old mails. i hope its just a bunch of false positives ;-)
thanks for looking this up.

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Wednesday, February 20, 2008 7:42:49 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 20/02/2008
Kaspersky Anti-Virus database records: 573587
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\

Scan Statistics:
Total number of scanned objects: 472659
Number of viruses found: 5
Number of infected objects: 68
Number of suspicious objects: 0
Duration of the scan process: 04:53:44

Infected Object Name / Virus Name / Last Action
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Comodo\Firewall Pro\cfplogdb.sdb Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Cookies\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Verlauf\History.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\NTUSER.DAT Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\Cookies\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Verlauf\History.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\NTUSER.DAT Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Anwendungsdaten\Mozilla\Firefox\Profiles\5y96usga.default\cert8.db Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Anwendungsdaten\Mozilla\Firefox\Profiles\5y96usga.default\flashgot.log Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Anwendungsdaten\Mozilla\Firefox\Profiles\5y96usga.default\formhistory.dat Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Anwendungsdaten\Mozilla\Firefox\Profiles\5y96usga.default\history.dat Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Anwendungsdaten\Mozilla\Firefox\Profiles\5y96usga.default\key3.db Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Anwendungsdaten\Mozilla\Firefox\Profiles\5y96usga.default\parent.lock Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Anwendungsdaten\Mozilla\Firefox\Profiles\5y96usga.default\search.sqlite Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Anwendungsdaten\Mozilla\Firefox\Profiles\5y96usga.default\urlclassifier2.sqlite Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Anwendungsdaten\Thunderbird\Profiles\fniz1bkl.default\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>] … /[From RBL: SORBS: sent directl … /[From "Arkangel" <[removed]>][Da … /Rechnung_Sign177138535545553187871.pdf.exe Infected: Trojan-Downloader.Win32.Nurech.bi skipped
C:\Dokumente und Einstellungen\Severus\Anwendungsdaten\Thunderbird\Profiles\fniz1bkl.default\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>] … /[From RBL: SORBS: sent directl … /[From "Arkangel" <[removed]>][Date Tue, 24 Apr 2007 20:07:12 +0200]/Rechnung.zip Infected: Trojan-Downloader.Win32.Nurech.bi skipped
C:\Dokumente und Einstellungen\Severus\Anwendungsdaten\Thunderbird\Profiles\fniz1bkl.default\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>] … /[From RBL: SORBS: sent directly from dynamic IP address * [[removed]][Date Sat, 20 Jan 2007 14:29:38 +0100]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
C:\Dokumente und Einstellungen\Severus\Anwendungsdaten\Thunderbird\Profiles\fniz1bkl.default\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>][Date Sun, 1 Oct 2006 19:51:17 + … /[From "Strongest Strongest" <[removed]>][Date Thu, 05 Oct 2006 21:58:43 +0200]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
C:\Dokumente und Einstellungen\Severus\Anwendungsdaten\Thunderbird\Profiles\fniz1bkl.default\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>][Date Sun, 1 Oct 2006 19:51:17 +0200]/html Infected: Trojan-Downloader.Win32.Nurech.bi skipped
C:\Dokumente und Einstellungen\Severus\Anwendungsdaten\Thunderbird\Profiles\fniz1bkl.default\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
C:\Dokumente und Einstellungen\Severus\Anwendungsdaten\Thunderbird\Profiles\fniz1bkl.default\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc Infected: Trojan-Downloader.Win32.Nurech.bi skipped
C:\Dokumente und Einstellungen\Severus\Anwendungsdaten\Thunderbird\Profiles\fniz1bkl.default\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt Infected: Trojan-Downloader.Win32.Nurech.bi skipped
C:\Dokumente und Einstellungen\Severus\Anwendungsdaten\Thunderbird\Profiles\fniz1bkl.default\Mail\Local Folders\9-AWA.sbd\Office Mail Berkeley mbox: infected - 8 skipped
C:\Dokumente und Einstellungen\Severus\Cookies\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Desktop\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>] … /[From RBL: SORBS: sent directl … /[From "Arkangel" <[removed]>][Da … /Rechnung_Sign177138535545553187871.pdf.exe Infected: Trojan-Downloader.Win32.Nurech.bi skipped
C:\Dokumente und Einstellungen\Severus\Desktop\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>] … /[From RBL: SORBS: sent directl … /[From "Arkangel" <[removed]>][Date Tue, 24 Apr 2007 20:07:12 +0200]/Rechnung.zip Infected: Trojan-Downloader.Win32.Nurech.bi skipped
C:\Dokumente und Einstellungen\Severus\Desktop\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>] … /[From RBL: SORBS: sent directly from dynamic IP address * [[removed]][Date Sat, 20 Jan 2007 14:29:38 +0100]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
C:\Dokumente und Einstellungen\Severus\Desktop\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>][Date Sun, 1 Oct 2006 19:51:17 + … /[From "Strongest Strongest" <[removed]>][Date Thu, 05 Oct 2006 21:58:43 +0200]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
C:\Dokumente und Einstellungen\Severus\Desktop\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>][Date Sun, 1 Oct 2006 19:51:17 +0200]/html Infected: Trojan-Downloader.Win32.Nurech.bi skipped
C:\Dokumente und Einstellungen\Severus\Desktop\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
C:\Dokumente und Einstellungen\Severus\Desktop\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc Infected: Trojan-Downloader.Win32.Nurech.bi skipped
C:\Dokumente und Einstellungen\Severus\Desktop\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt Infected: Trojan-Downloader.Win32.Nurech.bi skipped
C:\Dokumente und Einstellungen\Severus\Desktop\Mail\Local Folders\9-AWA.sbd\Office Mail Berkeley mbox: infected - 8 skipped
C:\Dokumente und Einstellungen\Severus\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Lokale Einstellungen\Anwendungsdaten\Mozilla\Firefox\Profiles\5y96usga.default\Cache\_CACHE_001_ Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Lokale Einstellungen\Anwendungsdaten\Mozilla\Firefox\Profiles\5y96usga.default\Cache\_CACHE_002_ Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Lokale Einstellungen\Anwendungsdaten\Mozilla\Firefox\Profiles\5y96usga.default\Cache\_CACHE_003_ Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Lokale Einstellungen\Anwendungsdaten\Mozilla\Firefox\Profiles\5y96usga.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Lokale Einstellungen\Verlauf\History.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Lokale Einstellungen\Verlauf\History.IE5\MSHist012008022020080221\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\Severus\NTUSER.DAT Object is locked skipped
C:\Dokumente und Einstellungen\Severus\NTUSER.DAT.LOG Object is locked skipped
C:\Programme\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Programme\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Programme\Alwil Software\Avast4\DATA\integ\avast.int Object is locked skipped
C:\Programme\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Programme\Cobian Backup 8\DB\log.txt Object is locked skipped
C:\Programme\Super Fast Shutdown\shutdown.exe Infected: not-a-virus:RiskTool.Win32.Shutdown.c skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{99ABE7E1-5A1B-4047-AAD3-1D3D1193AD6A}\RP176\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_630.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\System Volume Information\_restore{99ABE7E1-5A1B-4047-AAD3-1D3D1193AD6A}\RP176\change.log Object is locked skipped
E:\lager\programme\burntools\nero_6009_+_serial_+_German___Nero6___Nero_Version_6009\Nero-6.6.1.15a.exe/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
E:\lager\programme\burntools\nero_6009_+_serial_+_German___Nero6___Nero_Version_6009\Nero-6.6.1.15a.exe RAR: infected - 1 skipped
E:\lager\programme\fp2006-final-3.00-setup.exe/file1626 Infected: not-virus:BadJoke.JS.RJump skipped
E:\lager\programme\fp2006-final-3.00-setup.exe Inno: infected - 1 skipped
E:\lager\programme\superfast.zip/setup.exe/file1 Infected: not-a-virus:RiskTool.Win32.Shutdown.c skipped
E:\lager\programme\superfast.zip/setup.exe Infected: not-a-virus:RiskTool.Win32.Shutdown.c skipped
E:\lager\programme\superfast.zip ZIP: infected - 2 skipped
E:\RECYCLER\S-1-5-21-1614895754-1958367476-682003330-1004\De1\v9dtqdnq.default\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>] … /[From RBL: SORBS: sent directl … /[From "Arkangel" <[removed]>][Da … /Rechnung_Sign177138535545553187871.pdf.exe Infected: Trojan-Downloader.Win32.Nurech.bi skipped
E:\RECYCLER\S-1-5-21-1614895754-1958367476-682003330-1004\De1\v9dtqdnq.default\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>] … /[From RBL: SORBS: sent directl … /[From "Arkangel" <[removed]>][Date Tue, 24 Apr 2007 20:07:12 +0200]/Rechnung.zip Infected: Trojan-Downloader.Win32.Nurech.bi skipped
E:\RECYCLER\S-1-5-21-1614895754-1958367476-682003330-1004\De1\v9dtqdnq.default\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>] … /[From RBL: SORBS: sent directly from dynamic IP address * [[removed]][Date Sat, 20 Jan 2007 14:29:38 +0100]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
E:\RECYCLER\S-1-5-21-1614895754-1958367476-682003330-1004\De1\v9dtqdnq.default\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>][Date Sun, 1 Oct 2006 19:51:17 + … /[From "Strongest Strongest" <[removed]>][Date Thu, 05 Oct 2006 21:58:43 +0200]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
E:\RECYCLER\S-1-5-21-1614895754-1958367476-682003330-1004\De1\v9dtqdnq.default\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>][Date Sun, 1 Oct 2006 19:51:17 +0200]/html Infected: Trojan-Downloader.Win32.Nurech.bi skipped
E:\RECYCLER\S-1-5-21-1614895754-1958367476-682003330-1004\De1\v9dtqdnq.default\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
E:\RECYCLER\S-1-5-21-1614895754-1958367476-682003330-1004\De1\v9dtqdnq.default\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc Infected: Trojan-Downloader.Win32.Nurech.bi skipped
E:\RECYCLER\S-1-5-21-1614895754-1958367476-682003330-1004\De1\v9dtqdnq.default\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt Infected: Trojan-Downloader.Win32.Nurech.bi skipped
E:\RECYCLER\S-1-5-21-1614895754-1958367476-682003330-1004\De1\v9dtqdnq.default\Mail\Local Folders\9-AWA.sbd\Office Mail Berkeley mbox: infected - 8 skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP29\A0001447.ver Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP29\A0001448.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP29\A0001449.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP29\A0001450.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP29\A0001451.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP29\A0001452.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP29\A0001453.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP29\A0001454.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001463.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001464.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001465.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001466.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001467.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001468.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001469.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001470.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001471.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001472.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001473.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001474.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001475.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001476.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001477.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001478.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001479.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001480.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001481.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001482.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001483.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001484.ver Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001485.ver Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP31\A0001493.ver Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP31\A0001494.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP31\A0001495.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP31\A0001496.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP31\A0001497.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP31\A0001498.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP31\A0001499.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP31\A0001500.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP31\A0001501.ocx Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP31\A0001502.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP31\A0001503.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP31\A0001504.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP31\A0001505.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP31\A0001506.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP31\A0001507.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001551.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001552.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001553.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001554.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001555.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001556.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001557.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001558.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001559.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001560.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001561.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001562.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001563.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001564.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001565.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001566.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001567.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001568.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001569.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001570.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001571.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001572.ver Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001573.ver Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001574.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001575.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001576.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001577.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001578.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001579.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001580.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001581.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001582.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001583.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001584.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001585.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001586.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001587.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001588.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001589.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001590.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001591.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001592.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001593.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001594.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001595.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001596.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001597.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001598.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001599.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001600.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001601.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001602.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001603.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001604.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001605.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001606.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001607.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001616.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001617.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001618.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001619.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001620.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001621.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001622.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001623.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001624.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001625.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001626.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001627.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001628.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001629.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001630.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001631.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001632.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001633.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001634.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001635.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001636.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001637.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001638.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001639.ver Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001640.ver Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001683.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001684.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001685.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001686.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001687.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001688.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001689.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001690.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001691.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001692.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001693.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001694.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001695.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001696.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001697.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001698.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001699.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001700.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001701.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001702.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001703.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001704.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001705.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001706.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001707.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001708.ver Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001709.ver Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001710.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001711.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001718.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001719.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001720.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001721.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001722.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001723.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001724.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001725.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001726.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001727.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001728.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001729.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001730.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001731.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001732.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001733.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001734.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001735.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001736.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001737.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001738.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001739.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001740.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001741.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001742.ver Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001743.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001744.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001745.ver Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001790.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001791.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001792.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001793.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001794.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001795.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001796.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001797.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001798.ver Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001799.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001800.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001801.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001802.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001803.ver Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001804.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001805.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001806.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001807.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001808.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001809.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001810.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001811.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001812.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP48\A0002600.ver Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP48\A0002601.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP48\A0002602.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP48\A0002603.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP48\A0002604.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP48\A0002605.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP48\A0002606.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP48\A0002607.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP48\A0002608.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP48\A0002609.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP48\A0002610.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP48\A0002611.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP50\A0002906.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003619.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003620.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003621.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003622.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003623.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003624.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003625.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003626.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003627.ver Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003628.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003629.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003630.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003631.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003632.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003633.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003634.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003635.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003636.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003637.cat Object is locked skipped
E:\System Volume Information\_restore{99ABE7E1-5A1B-4047-AAD3-1D3D1193AD6A}\RP176\change.log Object is locked skipped
E:\trenzterratornado\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
E:\trenzterratornado\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
E:\Windrop\LamestBot.chan Object is locked skipped
E:\Windrop\LamestBot.notes Object is locked skipped
E:\Windrop\Lord_Voldebot.user Object is locked skipped
F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
F:\System Volume Information\_restore{99ABE7E1-5A1B-4047-AAD3-1D3D1193AD6A}\RP176\change.log Object is locked skipped
G:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
G:\System Volume Information\_restore{99ABE7E1-5A1B-4047-AAD3-1D3D1193AD6A}\RP176\change.log Object is locked skipped
G:\thunderbirdbackup\Profiles 2008-02-08 02;11;20.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 ( … /[From RBL: SORBS: sent directl … /[From "Arkangel" <[removed]>][Da … /Rechnung_Sign177138535545553187871.pdf.exe Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-08 02;11;20.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 ( … /[From RBL: SORBS: sent directl … /[From "Arkangel" <[removed]>][Date Tue, 24 Apr 2007 20:07:12 +0200]/Rechnung.zip Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-08 02;11;20.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 ( … /[From RBL: SORBS: sent directly from dynamic IP address * [[removed]][Date Sat, 20 Jan 2007 14:29:38 +0100]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-08 02;11;20.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" ][Date Thu, 05 Oct 2006 21:58:43 +0200]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-08 02;11;20.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>][Date Sun, 1 Oct 2006 19:51:17 +0200]/html Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-08 02;11;20.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-08 02;11;20.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-08 02;11;20.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-08 02;11;20.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-08 02;11;20.zip ZIP: infected - 9 skipped
G:\thunderbirdbackup\Profiles 2008-02-10 21;30;43.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 ( … /[From RBL: SORBS: sent directl … /[From "Arkangel" <[removed]>][Da … /Rechnung_Sign177138535545553187871.pdf.exe Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-10 21;30;43.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 ( … /[From RBL: SORBS: sent directl … /[From "Arkangel" <[removed]>][Date Tue, 24 Apr 2007 20:07:12 +0200]/Rechnung.zip Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-10 21;30;43.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 ( … /[From RBL: SORBS: sent directly from dynamic IP address * [[removed]][Date Sat, 20 Jan 2007 14:29:38 +0100]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-10 21;30;43.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" ][Date Thu, 05 Oct 2006 21:58:43 +0200]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-10 21;30;43.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>][Date Sun, 1 Oct 2006 19:51:17 +0200]/html Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-10 21;30;43.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-10 21;30;43.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-10 21;30;43.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-10 21;30;43.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-10 21;30;43.zip ZIP: infected - 9 skipped
G:\thunderbirdbackup\Profiles 2008-02-17 21;30;38.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 ( … /[From RBL: SORBS: sent directl … /[From "Arkangel" <[removed]>][Da … /Rechnung_Sign177138535545553187871.pdf.exe Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-17 21;30;38.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 ( … /[From RBL: SORBS: sent directl … /[From "Arkangel" <[removed]>][Date Tue, 24 Apr 2007 20:07:12 +0200]/Rechnung.zip Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-17 21;30;38.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 ( … /[From RBL: SORBS: sent directly from dynamic IP address * [[removed]][Date Sat, 20 Jan 2007 14:29:38 +0100]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-17 21;30;38.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" ][Date Thu, 05 Oct 2006 21:58:43 +0200]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-17 21;30;38.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>][Date Sun, 1 Oct 2006 19:51:17 +0200]/html Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-17 21;30;38.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-17 21;30;38.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-17 21;30;38.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-17 21;30;38.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-17 21;30;38.zip ZIP: infected - 9 skipped

Scan process completed.

—————————————————————
and here's the Hijack This logfile.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:44:45, on 20.02.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programme\TuneUp Utilities 2004\WinStylerThemeSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\Alwil Software\Avast4\aswUpdSv.exe
C:\Programme\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\Cobian Backup 8\cbInterface.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Programme\Comodo\Firewall\cfp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Wallperizer\Wallperizer.exe
C:\Programme\a-squared Free\a2service.exe
C:\Programme\Comodo\Firewall\cmdagent.exe
C:\Programme\Cobian Backup 8\cbService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\Internet Explorer\iexplore.exe
C:\Programme\Mozilla Firefox\firefox.exe
C:\Programme\Alwil Software\Avast4\ashMaiSv.exe
C:\Programme\Alwil Software\Avast4\ashWebSv.exe
C:\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Cobian Backup 8 interface] "C:\Programme\Cobian Backup 8\cbInterface.exe" -service
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Programme\Comodo\Firewall\cfp.exe" -s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Wallperizer.lnk = C:\Wallperizer\Wallperizer.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1193570037906
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1195995401562
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Programme\a-squared Free\a2service.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programme\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programme\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programme\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programme\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - COMODO - C:\Programme\Comodo\Firewall\cmdagent.exe
O23 - Service: Cobian Backup 8 Service (CobBMService) - Luis Cobian - C:\Programme\Cobian Backup 8\cbService.exe
O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Programme\SiSoftware\SiSoftware Sandra Lite XII.SP1\Win32\RpcDataSrv.exe
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Programme\SiSoftware\SiSoftware Sandra Lite XII.SP1\RpcSandraSrv.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Programme\TuneUp Utilities 2004\WinStylerThemeSvc.exe

–
End of file - 5870 bytes
Hi Severus,

This folder appears to contain cracked software which is illegal, and may have been modified to contain malware, please delete it:

E:\lager\programme\burntools\nero_6009_+_serial_+_German___Nero6___Nero_Version_6009

I suggest you use a free and safe alternative such as ImgBurn (which has a German translation available)

A program file which appears to be 1st Page 2006 has been flagged as containing a non-malicious 'joke' program:

E:\lager\programme\fp2006-final-3.00-setup.exe

It might be a false positive but to be safe, I recommend you delete it and download it again from the developer's site:
http://www.evrsoft.com/download.shtml


Some old emails have been flagged, I recommend you delete them. There appear to be two messages in your current Thunderbird email box, and three in your archive files.
The emails are all from From "Mr Myers, AWA President" <[removed]> and are dated Date Thu, 4 Aug 2005 00:43:51 +0200 - you should be able to use the Thunderbird search feature to locate these.

————————————————————————

You can now delete DSS.exe from your Desktop, also delete this folder:

C:\Deckard


Next click Start->Run and type cleanmgr in the box and press OK
Ensure the boxes for Recycle Bin, Temporary Files and Temporary Internet Files are checked, you can choose to check other boxes if you wish but they are not required.
Press OK and Yes to confirm


Create a new, clean System Restore point which you can use in case of future system problems:
Press Start->All Programs->Accessories->System Tools->System Restore
Select Create a restore point, then Next, type a name like All Clean then press the Create button and once it's done press Close

Now remove old, infected System Restore points:
Next click Start->Run and type cleanmgr in the box and press OK
Ensure the boxes for Recycle Bin, Temporary Files and Temporary Internet Files are checked, you can choose to check other boxes if you wish but they are not required.
Select the More Options tab, under System Restore press Clean up… and say Yes to the prompt
Press OK and Yes to confirm

————————————————————————

Once complete, please let me know if you had any problems with the instructions.
hi, I deleted the whole stuff (the mails right after i read the kaspersky log ;-) ) first page was directly from the eversoft homepage, so i suppose false positive, but deleted it nevertheless. old archives etc gone too.. just so in know, in case it happens again..was that smss.exe, that resided im config real malware ? thanks again for helping out.
Hi Severus,

Yes the smss.exe was real malware and it used the name of a legitimate Windows program to appear legitimate, but as you know it was in a different folder than the real smss.exe. It looks like it was a trojan downloader which downloads other malware onto your machine, and Comodo's outbound protection probably stopped the infection from becoming much worse.

I think your machine is clean of malware now, here are some tips to help you keep it that way:

Operating system vulnerabilities can easily be exploited by malware so please ensure your operating system is automatically kept up to date by using Windows Update:
Go to Start->Control Panel->Automatic Updates
Select Automatic and select a suitable schedule
Also, check that your antivirus and antispyware programs are set to automatically update daily.

You have a good antivirus program installed, however I recommend you also install antispyware software with real-time capabilities - this will protect you from a wider range of malware and also that it will protect you from system changes and spyware while you are working, not just removing malware after it has been installed. There are a range of paid-for and free packages available, a free one I can recommend is Windows Defender, available here:
http://www.microsoft.com/athome/security/s…re/default.mspx

Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

Please take care when downloading programs. One of the easiest ways to be infected is to download freeware/shareware programs which come laden with malware - this includes allowing websites to install browser plug-ins orActiveX controls. Before downloading, it is crucial to check whether the source is reputable.
One way to check is to use McAfee SiteAdvisor. Copy the domain name into the space provided and SiteAdvisor will give you a report on the website which can help you decide if it is safe. They also have a toolbar for IE and Firefox which adds this functionality to your browser.

Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.

Find out more about how to prevent infection in the future
http://forum.malwareremoval.com/viewtopic.php?p=33687

Please post back to let me know that you have read this, and if there are any further issues.
thank You for taking the time and helping. i tried kaspersky online once more and it still showed me some mails as trojan downloader, funny thing ist.. there arent any of those mails left. didnt find them anyway. they are at the average 3 years old. other scanners didnt show any infection. ( i tried bitdefender online ) and avast. but just to make sure i ll reset comodo defense + to paranoid mode ;-). i really appreciate your help. i'm not normally prone to getting malware, this was just the 3rd time in about 10 years, and i really hope to keep it that way ;-). thanks again.
You're most welcome :) Comodo is an excellent program and it's outbound protection can limit what malware is able to do on your machine - but of course it's best to stop malware getting on your machine in the first place - you can do this by being very careful with any downloads and keeping your OS and protection software up to date. Best of luck!
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI