View Full Version : Virumonde Removal - need help
WalkerTXRanger
2008-04-27, 16:37
Spybot S&D caught Virumonde but is not able to remove it properly. I hope you can help me. This is the Kaspersky Report.
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Sunday, April 27, 2008 2:56:08 PM
Operating System: Microsoft Windows Vista Professional, (Build 6000)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 27/04/2008
Kaspersky Anti-Virus database records: 727420
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
E:\
Scan Statistics:
Total number of scanned objects: 154640
Number of viruses found: 5
Number of infected objects: 15
Number of suspicious objects: 0
Duration of the scan process: 01:06:25
Infected Object Name / Virus Name / Last Action
C:\Boot\BCD Object is locked skipped
C:\Boot\BCD.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\NFWEVT.LOG Object is locked skipped
C:\Program Files\InstallShield Installation Information\{1007F41F-7D69-468E-8017-3849A5A973C2}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{1297C681-92D7-40EF-93BF-03F66EC5105C}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{17CBC505-D1AE-459D-B445-3D2000A85842}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{65706020-7B6F-41F2-8047-FC69579E386A}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{7EB114D8-207F-45AE-BABD-1669715F2630}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{986F64DC-FF15-449D-998F-EE3BCEC6666A}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{C6FA39A7-26B1-480A-BC74-6D17531AC222}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{CF5737AF-8550-4546-A69B-0EA9EF5A9B55}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{D728E945-256D-4477-B377-6BBA693714AC}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{DAC01CEE-5BAE-42D5-81FC-B687E84E8405}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{DB71210F-8314-4AE3-B7A7-EBAF85BD30E9}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{E7E836B8-4BDD-454F-82E6-5FEA17C83AD4}\setup.ilg Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVApp.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVError.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVVirus.log Object is locked skipped
C:\Program Files\PCDR5\pcd_cpp_gui.p5i Object is locked skipped
C:\ProgramData\Symantec\Common Client\settings.bak Object is locked skipped
C:\ProgramData\Symantec\Common Client\settings.dat Object is locked skipped
C:\ProgramData\Symantec\Shared\QBackup\index.qbs Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBConfig.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBDebug.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBDetect.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBNotify.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBRefr.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetCfg.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetCfg2.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetDev.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetLoc.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetUsr.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBStHash.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBValid.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\SPPolicy.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\SPStart.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\SPStop.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtErEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtMoEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtNvEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtScEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtTxFEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtViEvt.log Object is locked skipped
C:\ProgramData\Symantec\SubEng\submissions.idx Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDALRT.log Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDCON.log Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDDBG.log Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDFW.log Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDIDS.log Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDSYS.log Object is locked skipped
C:\SWTOOLS\APPLICATION.EVTX Object is locked skipped
C:\SWTOOLS\SECURITY.EVTX Object is locked skipped
C:\SWTOOLS\SETUP.EVTX Object is locked skipped
C:\SWTOOLS\SYSTEM.EVTX Object is locked skipped
C:\Users\Patrick\AppData\Local\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Users\Patrick\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT Object is locked skipped
C:\Users\Patrick\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db Object is locked skipped
C:\Users\Patrick\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db Object is locked skipped
C:\Users\Patrick\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db Object is locked skipped
C:\Users\Patrick\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db Object is locked skipped
C:\Users\Patrick\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db Object is locked skipped
C:\Users\Patrick\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db Object is locked skipped
C:\Users\Patrick\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat Object is locked skipped
C:\Users\Patrick\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.dat Object is locked skipped
C:\Users\Patrick\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DN896E64\zwjabb[1].htm Infected: Backdoor.Win32.Small.dnw skipped
C:\Users\Patrick\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Users\Patrick\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TGW3IW96\css4[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.qrd skipped
C:\Users\Patrick\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V4OM9PVQ\zjtkhlyzm[1].txt Infected: Trojan-Downloader.Win32.Agent.ncd skipped
C:\Users\Patrick\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WFTWBPYO\kriv[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.qre skipped
C:\Users\Patrick\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Users\Patrick\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat Object is locked skipped
C:\Users\Patrick\AppData\Local\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Users\Patrick\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 Object is locked skipped
C:\Users\Patrick\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 Object is locked skipped
C:\Users\Patrick\AppData\Local\Microsoft\Windows\UsrClass.dat{1f2794d0-6a72-11db-b2a9-0014220f8c51}.TM.blf Object is locked skipped
C:\Users\Patrick\AppData\Local\Microsoft\Windows\UsrClass.dat{1f2794d0-6a72-11db-b2a9-0014220f8c51}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\Patrick\AppData\Local\Microsoft\Windows\UsrClass.dat{1f2794d0-6a72-11db-b2a9-0014220f8c51}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Users\Patrick\AppData\Local\Microsoft\Windows Sidebar\Settings.ini Object is locked skipped
C:\Users\Patrick\AppData\Local\Temp\efcDUkIc.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qrd skipped
C:\Users\Patrick\AppData\Local\Temp\FXSAPIDebugLogFile.txt Object is locked skipped
C:\Users\Patrick\AppData\Local\Temp\Low\~DFE27.tmp Object is locked skipped
C:\Users\Patrick\AppData\Local\Temp\oxwgdxvg.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qre skipped
C:\Users\Patrick\AppData\Local\Temp\tmp00015aeb Infected: Packed.Win32.Monder.gen skipped
C:\Users\Patrick\AppData\Local\Temp\tmp00015caf Infected: Packed.Win32.Monder.gen skipped
C:\Users\Patrick\AppData\Local\Temp\tmp00017686 Infected: Packed.Win32.Monder.gen skipped
C:\Users\Patrick\AppData\Local\Temp\tmp00018aa2 Infected: Packed.Win32.Monder.gen skipped
C:\Users\Patrick\AppData\Local\Temp\tmp0001ab3c Infected: Packed.Win32.Monder.gen skipped
C:\Users\Patrick\AppData\Local\Temp\tmp000245d5 Infected: Packed.Win32.Monder.gen skipped
C:\Users\Patrick\AppData\Local\Temp\tmp00046ac3 Infected: Packed.Win32.Monder.gen skipped
C:\Users\Patrick\AppData\Local\Temp\tmp0004814f Infected: Packed.Win32.Monder.gen skipped
C:\Users\Patrick\AppData\Local\Temp\urqRIyYr.dll Infected: Packed.Win32.Monder.gen skipped
C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Cookies\index.dat Object is locked skipped
C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.dat Object is locked skipped
C:\Users\Patrick\NTUSER.DAT Object is locked skipped
C:\Users\Patrick\ntuser.dat.LOG1 Object is locked skipped
C:\Users\Patrick\ntuser.dat.LOG2 Object is locked skipped
C:\Users\Patrick\NTUSER.DAT{3d4e88f1-6a70-11db-b1ba-d64300c9c793}.TM.blf Object is locked skipped
C:\Users\Patrick\NTUSER.DAT{3d4e88f1-6a70-11db-b1ba-d64300c9c793}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\Patrick\NTUSER.DAT{3d4e88f1-6a70-11db-b1ba-d64300c9c793}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\bthservsdp.dat Object is locked skipped
C:\Windows\Debug\PASSWD.LOG Object is locked skipped
C:\Windows\Debug\sam.log Object is locked skipped
C:\Windows\Debug\WIA\wiatrace.log Object is locked skipped
C:\Windows\GRLP.LOG.txt Object is locked skipped
C:\Windows\KB925902.LOG.txt Object is locked skipped
C:\Windows\KB929123.LOG.txt Object is locked skipped
C:\Windows\KB929399.LOG.txt Object is locked skipped
C:\Windows\KB929577.LOG.txt Object is locked skipped
C:\Windows\KB929637.LOG.txt Object is locked skipped
C:\Windows\KB929735.LOG.txt Object is locked skipped
C:\Windows\KB929763.LOG.txt Object is locked skipped
C:\Windows\KB929777.LOG.txt Object is locked skipped
C:\Windows\KB929916.LOG.txt Object is locked skipped
C:\Windows\KB930163.LOG.txt Object is locked skipped
C:\Windows\KB930178.LOG.txt Object is locked skipped
C:\Windows\KB930193.LOG.txt Object is locked skipped
C:\Windows\KB930585.LOG.txt Object is locked skipped
C:\Windows\KB930857.LOG.txt Object is locked skipped
C:\Windows\KB931099.LOG.txt Object is locked skipped
C:\Windows\KB931213.LOG.txt Object is locked skipped
C:\Windows\KB931573.LOG.txt Object is locked skipped
C:\Windows\KB931621.LOG.txt Object is locked skipped
C:\Windows\KB933579.LOG.txt Object is locked skipped
C:\Windows\KB933729.LOG.txt Object is locked skipped
C:\Windows\KB933928.LOG.txt Object is locked skipped
C:\Windows\KB935807.LOG.txt Object is locked skipped
C:\Windows\KB936003.LOG.txt Object is locked skipped
C:\Windows\KB936021.LOG.txt Object is locked skipped
C:\Windows\KB936357.LOG.txt Object is locked skipped
C:\Windows\KB936782.LOG.txt Object is locked skipped
C:\Windows\KB936824.LOG.txt Object is locked skipped
C:\Windows\KB936825.LOG.txt Object is locked skipped
C:\Windows\KB937077.LOG.txt Object is locked skipped
C:\Windows\KB937500.LOG.txt Object is locked skipped
C:\Windows\KB938123.LOG.txt Object is locked skipped
C:\Windows\KB938127.LOG.txt Object is locked skipped
C:\Windows\KB938194.LOG.txt Object is locked skipped
C:\Windows\KB938952.LOG.txt Object is locked skipped
C:\Windows\KB938979.LOG.txt Object is locked skipped
C:\Windows\KB939159.LOG.txt Object is locked skipped
C:\Windows\KB939165.LOG.txt Object is locked skipped
C:\Windows\KB941202.LOG.txt Object is locked skipped
C:\Windows\KB941568.LOG.txt Object is locked skipped
C:\Windows\KB941569.LOG.txt Object is locked skipped
C:\Windows\KB941600.LOG.txt Object is locked skipped
C:\Windows\KB941644.LOG.txt Object is locked skipped
C:\Windows\KB941649.LOG.txt Object is locked skipped
C:\Windows\KB941651.LOG.txt Object is locked skipped
C:\Windows\KB942615.LOG.txt Object is locked skipped
C:\Windows\KB942624.LOG.txt Object is locked skipped
C:\Windows\KB942763.LOG.txt Object is locked skipped
C:\Windows\KB943078.LOG.txt Object is locked skipped
C:\Windows\KB943302.LOG.txt Object is locked skipped
C:\Windows\KB943411.LOG.txt Object is locked skipped
C:\Windows\KB943412.LOG.txt Object is locked skipped
C:\Windows\KB943899.LOG.txt Object is locked skipped
C:\Windows\Logs\DPX\setupact.log Object is locked skipped
C:\Windows\Logs\DPX\setuperr.log Object is locked skipped
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe.config Object is locked skipped
C:\Windows\Panther\UnattendGC\diagerr.xml Object is locked skipped
C:\Windows\Panther\UnattendGC\diagwrn.xml Object is locked skipped
C:\Windows\Panther\UnattendGC\setupact.log Object is locked skipped
C:\Windows\Panther\UnattendGC\setuperr.log Object is locked skipped
C:\Windows\security\database\secedit.sdb Object is locked skipped
C:\Windows\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\catroot2\edb.log Object is locked skipped
C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\config\COMPONENTS Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG1 Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG2 Object is locked skipped
C:\Windows\System32\config\DEFAULT Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG1 Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG2 Object is locked skipped
C:\Windows\System32\config\SAM Object is locked skipped
C:\Windows\System32\config\SAM.LOG1 Object is locked skipped
C:\Windows\System32\config\SAM.LOG2 Object is locked skipped
C:\Windows\System32\config\SECURITY Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG1 Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG2 Object is locked skipped
C:\Windows\System32\config\SOFTWARE Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG1 Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG2 Object is locked skipped
C:\Windows\System32\config\SYSTEM Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG1 Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG2 Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TM.blf Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000003.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000004.regtrans-ms Object is locked skipped
C:\Windows\System32\LogFiles\Scm\SCM.EVM Object is locked skipped
C:\Windows\System32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\Windows\System32\restore\MachineGuid.txt Object is locked skipped
C:\Windows\System32\spool\SpoolerETW.etl Object is locked skipped
C:\Windows\System32\sysprep\Panther\diagerr.xml Object is locked skipped
C:\Windows\System32\sysprep\Panther\diagwrn.xml Object is locked skipped
C:\Windows\System32\sysprep\Panther\setupact.log Object is locked skipped
C:\Windows\System32\sysprep\Panther\setuperr.log Object is locked skipped
C:\Windows\System32\wbem\AutoRecover\10A9EB2C94277C0A1A6143B54809F210.mof Object is locked skipped
C:\Windows\System32\wbem\AutoRecover\21D7529435092A1DD242FD6ACF494493.mof Object is locked skipped
C:\Windows\System32\wbem\AutoRecover\2B8B1A8B0ACD3EE28B421D3918DC1F29.mof Object is locked skipped
C:\Windows\System32\wbem\AutoRecover\3460B7617E0429A960E481B197F238A3.mof Object is locked skipped
C:\Windows\System32\wbem\AutoRecover\4D9F92C0437DBC456F4433CDD8506F52.mof Object is locked skipped
C:\Windows\System32\wbem\AutoRecover\5774C77265BE4C55B5C6C9718979E015.mof Object is locked skipped
C:\Windows\System32\wbem\AutoRecover\8A20D7181B570E2E2142FB6261D170A2.mof Object is locked skipped
C:\Windows\System32\wbem\AutoRecover\B8F066315788F9A2DF744CF3A9F7F3D6.mof Object is locked skipped
C:\Windows\System32\wbem\AutoRecover\E478A5DB75C9721E744C05D78DBACFD3.mof Object is locked skipped
C:\Windows\System32\wbem\AutoRecover\E9D8A460B2C986DD5FF19F299F4A27EC.mof Object is locked skipped
C:\Windows\System32\wbem\Logs\WMITracing.log Object is locked skipped
C:\Windows\System32\wbem\Repository\INDEX.BTR Object is locked skipped
C:\Windows\System32\wbem\Repository\MAPPING1.MAP Object is locked skipped
C:\Windows\System32\wbem\Repository\MAPPING2.MAP Object is locked skipped
C:\Windows\System32\wbem\Repository\OBJECTS.DATA Object is locked skipped
C:\Windows\System32\winevt\Logs\Application.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\DFS Replication.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\HardwareEvents.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Internet Explorer.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Key Management Service.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Networking%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-DriverFrameworks-UserMode%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Help%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-International%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-LanguagePackSetup%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-MUI%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Resolver%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Leak-Diagnostic%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-RestartManager%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-TaskScheduler%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-UAC%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-UAC-FileVirtualization%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-WindowsUpdateClient%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-WLAN-AutoConfig%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\ODiag.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\OSession.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Security.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\SETUP.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\System.evtx Object is locked skipped
C:\Windows\Tasks\Auf Updates für Windows Live Toolbar prüfen.job Object is locked skipped
C:\Windows\Tasks\SCHEDLGU.TXT Object is locked skipped
C:\Windows\WindowsUpdate.log Object is locked skipped
C:\Windows\winsxs\x86_microsoft-windows-n..n_service_datastore_31bf3856ad364e35_6.0.6000.16386_none_cef7ceb03914a67f\dnary.xsd Object is locked skipped
Scan process completed.
------------------------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:28:02, on 27.04.2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Lenovo\NPDIRECT\tpfnf7sp.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
C:\Windows\System32\TpShocks.exe
C:\Program Files\ThinkPad\Utilities\EZEJMNAP.EXE
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
C:\Program Files\ThinkVantage\PrdCtr\LPMGR.EXE
C:\Program Files\ThinkVantage\AMSG\Amsg.exe
C:\Program Files\Lenovo\Drag-to-Disc\DrgToDsc.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\ThinkVantage\PrdCtr\LPMLCHK.EXE
C:\Program Files\Lenovo\Client Security Solution\cssauth.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Programme\Winamp\winampa.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Lenovo\Client Security Solution\password_manager.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.live.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo.live.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - c:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Password Manager Browser Helper Object - {BF468356-BB7E-42D7-9F15-4F3B9BCFCED2} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - c:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [TPFNF7] C:\PROGRA~1\Lenovo\NPDIRECT\TPFNF7SP.exe /r
O4 - HKLM\..\Run: [PWMTRV] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWMTR32V.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BTVLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LenovoOobeOffers] c:\SWTOOLS\LenovoWelcome\LenovoOobeOffers.exe /filePath="c:\swshare\firstrun.txt"
O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [AwaySch] C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe
O4 - HKLM\..\Run: [AMSG] C:\Program Files\ThinkVantage\AMSG\Amsg.exe /startup
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Lenovo\Drag-to-Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
O4 - HKLM\..\Run: [IaNvSrv] C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [MMReminderService] C:\Program Files\Mindjet\MindManager 7\MMReminderService.exe
O4 - HKLM\..\Run: [LPMailChecker] C:\PROGRA~1\THINKV~2\PrdCtr\LPMLCHK.exe
O4 - HKLM\..\Run: [cssauth] "C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" silent
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Programme\Winamp\winampa.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\Patrick\AppData\Local\Temp\opnlKdcC.dll,#1
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\Patrick\AppData\Local\Temp\efcDUkIc.dll,c
O4 - HKCU\..\Run: [BM23cd9b82] Rundll32.exe "C:\Users\Patrick\AppData\Local\Temp\gkucvtbb.dll",s
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETZWERKDIENST')
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: LenovoRegistration.lnk = C:\SWTOOLS\LenovoWelcome\LenovoRegistration.cmd
O4 - Global Startup: VPN Client.lnk = ?
O8 - Extra context menu item: &Windows Live Search - res://c:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
O9 - Extra 'Tools' menuitem: Lenovo Password Manager... - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
O13 - Gopher Prefix:
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\Windows\system32\AEADISRV.EXE
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\Windows\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: IPS-Basisservice (IPSSVC) - Lenovo Group Limited - C:\Windows\system32\IPSSVC.EXE
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\program files\lenovo\system update\suservice.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\Windows\System32\TPHDEXLG.exe
O23 - Service: Anzeige am Bildschirm (TPHKSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
O23 - Service: TSS Core Service (TSSCoreService) - Lenovo - C:\Program Files\Lenovo\Client Security Solution\tvttcsd.exe
O23 - Service: TVT Backup Protection Service - Unknown owner - C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe
O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
O23 - Service: TVT Scheduler - Lenovo Group Limited - c:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
O23 - Service: tvtnetwk - Unknown owner - C:\Program Files\Lenovo\Rescue and Recovery\ADM\IUService.exe
O23 - Service: TVT Windows Update Monitor (TVT_UpdateMonitor) - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\UpdateMonitor.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 14196 bytes
Rorschach112
2008-04-27, 17:06
Hello
Please download ATF Cleaner (http://www.atribune.org/ccount/click.php?id=1) by Atribune.
This program is for XP and Windows 2000 only
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
Please download the OTMoveIt2 by OldTimer (http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe).
Save it to your desktop.
Please double-click OTMoveIt2.exe to run it.
Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
[kill explorer]
C:\Users\Patrick\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DN896E64\zwjabb[1].htm
C:\Users\Patrick\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TGW3IW96\css4[1]
C:\Users\Patrick\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V4OM9PVQ\zjtkhlyzm[1].txt
C:\Users\Patrick\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WFTWBPYO\kriv[1]
C:\Users\Patrick\AppData\Local\Temp\efcDUkIc.dll
C:\Users\Patrick\AppData\Local\Temp\oxwgdxvg.dll
C:\Users\Patrick\AppData\Local\Temp\tmp00015aeb
C:\Users\Patrick\AppData\Local\Temp\tmp00015caf
C:\Users\Patrick\AppData\Local\Temp\tmp00017686
C:\Users\Patrick\AppData\Local\Temp\tmp00018aa2
C:\Users\Patrick\AppData\Local\Temp\tmp0001ab3c
C:\Users\Patrick\AppData\Local\Temp\tmp000245d5
C:\Users\Patrick\AppData\Local\Temp\tmp00046ac3
C:\Users\Patrick\AppData\Local\Temp\tmp0004814f
C:\Users\Patrick\AppData\Local\Temp\urqRIyYr.dll
purity
[start explorer]
Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
Click the red Moveit! button.
A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
Reboot and do this
Please visit this webpage for instructions for downloading and running ComboFix:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
This includes installing the Windows XP Recovery Console in case you have not installed it yet.
for more information on the Windows XP Recovery Console read http://support.microsoft.com/kb/314058. once you install the Recovery Console, when you reboot your computer, right after reboot, you'll see the option for the Recovery Console now as well. Don't select Recovery Console as we don't need it. By default, your main OS is selected there. The screen stays for 2 seconds and then it proceeds to load Windows. that is normal.
Post the log from ComboFix when you've accomplished that, along with a new HijackThis log.
WalkerTXRanger
2008-04-27, 17:10
Thank you for the quick response! I use Windows Vista, though. Will those programs work with it since you said in your post "XP only".
Rorschach112
2008-04-27, 17:14
Yes they work, need to change that sorry :)
WalkerTXRanger
2008-04-27, 18:15
I executed all the programs and attached the log files below. Thank you a lot for your help!
------------------
OTMoveIT Log
Explorer killed successfully
< C:\Users\Patrick\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DN896E64\zwjabb[1].htm >
File/Folder C:\Users\Patrick\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DN896E64\zwjabb[1].htm not found.
< C:\Users\Patrick\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TGW3IW96\css4[1] >
File/Folder C:\Users\Patrick\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TGW3IW96\css4[1] not found.
< C:\Users\Patrick\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V4OM9PVQ\zjtkhlyzm[1].txt >
File/Folder C:\Users\Patrick\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V4OM9PVQ\zjtkhlyzm[1].txt not found.
< C:\Users\Patrick\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WFTWBPYO\kriv[1] >
C:\Users\Patrick\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WFTWBPYO\kriv[1] moved successfully.
DllUnregisterServer procedure not found in C:\Users\Patrick\AppData\Local\Temp\efcDUkIc.dll
C:\Users\Patrick\AppData\Local\Temp\efcDUkIc.dll NOT unregistered.
File move failed. C:\Users\Patrick\AppData\Local\Temp\efcDUkIc.dll scheduled to be moved on reboot.
DllUnregisterServer procedure not found in C:\Users\Patrick\AppData\Local\Temp\oxwgdxvg.dll
C:\Users\Patrick\AppData\Local\Temp\oxwgdxvg.dll NOT unregistered.
C:\Users\Patrick\AppData\Local\Temp\oxwgdxvg.dll moved successfully.
C:\Users\Patrick\AppData\Local\Temp\tmp00015aeb moved successfully.
C:\Users\Patrick\AppData\Local\Temp\tmp00015caf moved successfully.
C:\Users\Patrick\AppData\Local\Temp\tmp00017686 moved successfully.
C:\Users\Patrick\AppData\Local\Temp\tmp00018aa2 moved successfully.
C:\Users\Patrick\AppData\Local\Temp\tmp0001ab3c moved successfully.
C:\Users\Patrick\AppData\Local\Temp\tmp000245d5 moved successfully.
C:\Users\Patrick\AppData\Local\Temp\tmp00046ac3 moved successfully.
C:\Users\Patrick\AppData\Local\Temp\tmp0004814f moved successfully.
File/Folder C:\Users\Patrick\AppData\Local\Temp\urqRIyYr.dll not found.
< purity >
Explorer started successfully
OTMoveIt2 by OldTimer - Version 1.0.4.1 log created on 04272008_163311
--------------------------------------
ComboFix 08-04-26.3 - Patrick 2008-04-27 16:57:18.1 - NTFSx86
Microsoft® Windows Vista™ Business 6.0.6000.0.1252.1.1031.18.1800 [GMT 2:00]
ausgeführt von:: C:\Users\Patrick\Desktop\ComboFix.exe
* Neuer Wiederherstellungspunkt wurde erstellt
.
((((((((((((((((((((((( Dateien erstellt von 2008-03-27 bis 2008-04-27 ))))))))))))))))))))))))))))))
.
2008-04-27 16:33 . 2008-04-27 16:33 <DIR> d-------- C:\_OTMoveIt
2008-04-27 15:46 . 2008-04-27 15:46 <DIR> d-------- C:\_SMA
2008-04-27 15:27 . 2008-04-27 15:27 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-27 13:17 . 2008-04-27 13:17 <DIR> d-------- C:\Windows\System32\Kaspersky Lab
2008-04-27 11:15 . 2008-04-27 11:29 <DIR> d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-04-27 11:15 . 2008-04-27 11:29 <DIR> d-------- C:\ProgramData\Spybot - Search & Destroy
2008-04-27 11:15 . 2008-04-27 11:15 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-27 01:13 . 2008-04-27 01:13 <DIR> d-------- C:\Program Files\TeXnicCenter
2008-04-27 01:07 . 2008-04-27 01:07 <DIR> d-------- C:\Users\Patrick\AppData\Roaming\MiKTeX
2008-04-27 00:51 . 2008-04-27 01:04 <DIR> d-------- C:\Program Files\MiKTeX 2.7
2008-04-26 15:14 . 2008-04-26 15:14 194,560 --a------ C:\Windows\System32\WebClnt.dll
2008-04-26 15:14 . 2008-04-26 15:14 110,080 --a------ C:\Windows\System32\drivers\mrxdav.sys
2008-04-26 15:13 . 2008-04-26 15:13 1,060,920 --a------ C:\Windows\System32\drivers\ntfs.sys
2008-04-26 15:06 . 2008-04-26 15:06 2,027,008 --a------ C:\Windows\System32\win32k.sys
2008-04-26 15:05 . 2008-04-26 15:05 4,247,552 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-04-26 15:05 . 2008-04-26 15:05 1,686,528 --a------ C:\Windows\System32\gameux.dll
2008-04-26 15:05 . 2008-04-26 15:05 296,448 --a------ C:\Windows\System32\gdi32.dll
2008-04-26 15:04 . 2008-04-26 15:04 558,080 --a------ C:\Windows\System32\oleaut32.dll
2008-04-26 15:03 . 2008-04-26 15:03 148,992 --a------ C:\Windows\System32\drivers\ks.sys
2008-04-26 15:03 . 2008-04-26 15:03 83,968 --a------ C:\Windows\System32\dnsrslvr.dll
2008-04-26 15:03 . 2008-04-26 15:03 24,576 --a------ C:\Windows\System32\dnscacheugc.exe
2008-04-26 14:59 . 2008-04-26 14:59 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-04-26 14:58 . 2008-04-26 14:58 99,840 --a------ C:\Windows\System32\poqexec.exe
2008-04-26 11:07 . 2008-04-27 16:37 27,525 --a------ C:\Users\Patrick\AppData\Roaming\nvModes.dat
2008-04-26 08:37 . 2008-04-26 08:37 1,712,984 --a------ C:\Windows\System32\wuaueng.dll
2008-04-26 08:37 . 2008-04-26 08:37 1,524,224 --a------ C:\Windows\System32\wucltux.dll
2008-04-26 08:37 . 2008-04-26 08:37 53,080 --a------ C:\Windows\System32\wuauclt.exe
2008-04-26 08:37 . 2008-04-26 08:37 43,352 --a------ C:\Windows\System32\wups2.dll
2008-04-26 08:36 . 2008-04-26 08:36 549,720 --a------ C:\Windows\System32\wuapi.dll
2008-04-26 08:36 . 2008-04-26 08:36 163,000 --a------ C:\Windows\System32\wuwebv.dll
2008-04-26 08:36 . 2008-04-26 08:36 80,896 --a------ C:\Windows\System32\wudriver.dll
2008-04-26 08:36 . 2008-04-26 08:36 33,624 --a------ C:\Windows\System32\wups.dll
2008-04-26 08:36 . 2008-04-26 08:36 31,232 --a------ C:\Windows\System32\wuapp.exe
2008-04-26 08:25 . 2008-04-26 08:25 <DIR> d-------- C:\Program Files\Common Files\Deterministic Networks
2008-04-26 08:25 . 2007-01-31 13:45 127,376 --a------ C:\Windows\System32\drivers\dne2000.sys
2008-04-26 08:25 . 2007-01-31 13:45 101,904 --a------ C:\Windows\System32\dneinobj.dll
2008-04-26 08:24 . 2008-04-26 08:24 <DIR> d-------- C:\Program Files\Cisco Systems
2008-04-26 08:24 . 2008-04-26 08:26 1,593 --a------ C:\Windows\VPNInstall.MIF
2008-04-25 17:08 . 2008-04-25 17:27 <DIR> d-------- C:\Installs
2008-04-25 16:40 . 2008-04-25 16:47 <DIR> d-------- C:\Lebenslauf
2008-04-25 16:33 . 2008-04-25 16:33 <DIR> d-------- C:\Users\Patrick\AppData\Roaming\GMX
2008-04-25 16:33 . 2008-04-25 16:33 <DIR> d-------- C:\Users\All Users\GMX
2008-04-25 16:33 . 2008-04-25 16:33 <DIR> d-------- C:\ProgramData\GMX
2008-04-25 16:33 . 2008-04-25 16:33 <DIR> d-------- C:\Program Files\GMX
2008-04-25 16:33 . 2008-04-01 12:54 90,112 --a------ C:\Windows\System32\UIGMXMON.DLL
2008-04-25 11:02 . 2008-04-25 11:02 <DIR> d-------- C:\Users\Patrick\AppData\Roaming\Leadertech
2008-04-25 10:59 . 2008-04-26 10:26 <DIR> d-------- C:\Users\Patrick\.freemind
2008-04-25 10:40 . 2008-04-25 10:40 <DIR> d-------- C:\Users\Patrick\AppData\Roaming\Talkback
2008-04-25 09:58 . 2008-04-25 09:59 <DIR> d-------- C:\Users\Patrick\AppData\Roaming\Thunderbird
2008-04-25 09:58 . 2008-04-25 09:58 <DIR> d-------- C:\Program Files\Mozilla Thunderbird
2008-04-25 09:47 . 2008-04-25 11:02 <DIR> d-------- C:\Program Files\FreeMind
2008-04-25 01:14 . 2008-04-27 11:31 <DIR> dr------- C:\MPICC
2008-04-25 01:06 . 2008-02-03 09:20 47,680 --a------ C:\Windows\System32\drivers\tvtumon.sys
2008-04-25 00:41 . 2008-04-25 00:43 <DIR> d-------- C:\Users\Patrick\AppData\Roaming\Winamp
2008-04-25 00:41 . 2008-04-25 00:42 <DIR> d-------- C:\Program Files\Winamp
2008-04-25 00:13 . 2008-04-26 16:06 <DIR> d-------- C:\Users\Patrick\AppData\Roaming\skypePM
2008-04-25 00:13 . 2008-04-25 00:13 32 --a------ C:\Users\All Users\ezsid.dat
2008-04-25 00:13 . 2008-04-25 00:13 32 --a------ C:\ProgramData\ezsid.dat
2008-04-25 00:11 . 2008-04-26 23:04 <DIR> d-------- C:\Users\Patrick\AppData\Roaming\Skype
2008-04-25 00:10 . 2008-04-25 00:10 <DIR> d-------- C:\Users\All Users\Skype
2008-04-25 00:10 . 2008-04-25 00:10 <DIR> d-------- C:\ProgramData\Skype
2008-04-25 00:10 . 2008-04-25 00:10 <DIR> d-------- C:\Program Files\Skype
2008-04-25 00:10 . 2008-04-25 00:10 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-04-25 00:07 . 2008-04-27 16:37 <DIR> d-------- C:\Users\Patrick\AppData\Roaming\OpenOffice.org2
2008-04-24 23:56 . 2008-04-25 00:16 <DIR> d-------- C:\Program Files\Mozilla Firefox 3 Beta 5
2008-04-24 23:53 . 2008-04-27 16:36 2,080 --a------ C:\Windows\System32\ICAutoUpdate.log.bak
2008-04-24 23:46 . 2008-04-26 08:30 213,757,563 --a------ C:\sysiclog.txt.bak
2008-04-24 20:11 . 2008-04-24 20:11 <DIR> d-------- C:\Program Files\Common Files\ThinkVantage Fingerprint Software
2008-04-24 20:07 . 2008-04-24 20:07 33,536 --a------ C:\Windows\System32\drivers\tvtfilter.sys
2008-04-24 19:51 . 2008-04-24 19:51 390,144 --a------ C:\Windows\System32\wlangpui.dll
2008-04-24 19:51 . 2008-04-24 19:51 225,792 --a------ C:\Windows\System32\dot3gpui.dll
2008-04-24 19:51 . 2008-04-24 19:51 223,526 --a------ C:\Windows\System32\onex.tmf
2008-04-24 19:51 . 2008-04-24 19:51 162,816 --a------ C:\Windows\System32\onex.dll
2008-04-24 19:51 . 2008-04-24 19:51 146,944 --a------ C:\Windows\System32\dot3svc.dll
2008-04-24 19:51 . 2008-04-24 19:51 141,824 --a------ C:\Windows\System32\dot3ui.dll
2008-04-24 19:51 . 2008-04-24 19:51 72,192 --a------ C:\Windows\System32\dot3msm.dll
2008-04-24 19:51 . 2008-04-24 19:51 45,568 --a------ C:\Windows\System32\dot3dlg.dll
2008-04-24 19:51 . 2008-04-24 19:51 26,112 --a------ C:\Windows\System32\dot3api.dll
2008-04-24 19:50 . 2008-04-24 19:51 199,680 --a------ C:\Windows\System32\wlanui.dll
2008-04-24 19:48 . 2008-04-24 19:48 54,784 --a------ C:\Windows\System32\drivers\i8042prt.sys
2008-04-24 19:48 . 2008-04-24 19:48 35,512 --a------ C:\Windows\System32\drivers\kbdclass.sys
2008-04-24 19:46 . 2008-04-24 19:46 <DIR> d-------- C:\Users\All Users\Intel
2008-04-24 19:46 . 2008-04-24 19:46 <DIR> d-------- C:\ProgramData\Intel
2008-04-24 19:46 . 2008-04-24 19:46 <DIR> d-------- C:\Program Files\Cisco
2008-04-24 19:41 . 2008-04-24 19:41 188 --a------ C:\Windows\x
2008-04-24 18:34 . 2008-04-25 16:54 <DIR> d-------- C:\Uni
2008-04-24 18:21 . 2008-04-25 11:36 <DIR> d-------- C:\MP3s
2008-04-24 17:55 . 2008-04-24 17:55 47 --a------ C:\Windows\System32\drivers\IBM_7663_PJG.MRK
2008-04-24 17:38 . 2008-04-24 17:38 <DIR> d-------- C:\Program Files\OpenOffice.org 2.4
2008-04-24 17:29 . 2008-04-24 17:29 <DIR> d-------- C:\Users\All Users\Mindjet
2008-04-24 17:29 . 2008-04-24 17:29 <DIR> d-------- C:\ProgramData\Mindjet
2008-04-24 17:29 . 2008-04-24 17:29 <DIR> d-------- C:\Program Files\Mindjet
2008-04-24 17:29 . 2004-12-07 07:11 258,352 --a------ C:\Windows\System32\unicows.dll
2008-04-24 17:29 . 2006-01-30 09:32 5,632 --a------ C:\Windows\System32\pxc25pm.dll
2008-04-24 17:28 . 2008-04-24 17:28 16 --a------ C:\Windows\System32\coh.cache
2008-04-24 17:18 . 2008-04-24 17:18 0 --a------ C:\Windows\nsreg.dat
2008-04-24 17:04 . 2008-04-24 23:48 <DIR> d-------- C:\Users\Patrick\AppData\Roaming\Lenovo
2008-04-24 17:00 . 2006-11-02 15:04 <DIR> dr------- C:\Users\Patrick\Videos
2008-04-24 17:00 . 2008-04-24 17:02 <DIR> dr------- C:\Users\Patrick\Searches
2008-04-24 17:00 . 2006-11-02 15:04 <DIR> dr------- C:\Users\Patrick\Saved Games
2008-04-24 17:00 . 2006-11-02 15:04 <DIR> dr------- C:\Users\Patrick\Pictures
2008-04-24 17:00 . 2006-11-02 15:04 <DIR> dr------- C:\Users\Patrick\Music
2008-04-24 17:00 . 2008-04-24 17:02 <DIR> dr------- C:\Users\Patrick\Links
2008-04-24 17:00 . 2008-04-27 00:41 <DIR> dr------- C:\Users\Patrick\Downloads
2008-04-24 17:00 . 2008-04-25 00:02 <DIR> dr------- C:\Users\Patrick\Documents
2008-04-24 17:00 . 2006-11-02 15:04 <DIR> dr------- C:\Users\Patrick\Contacts
2008-04-24 17:00 . 2006-11-02 15:04 <DIR> d--h----- C:\Users\Patrick\AppData
2008-04-24 17:00 . 2008-04-26 08:25 <DIR> d-------- C:\Users\Patrick
2008-04-24 17:00 . 2008-04-24 17:00 <DIR> d-------- C:\Program Files\Windows Live Toolbar
2008-04-24 17:00 . 2008-04-24 17:08 524,288 --ahs---- C:\Users\Patrick\NTUSER.DAT{3d4e88f1-6a70-11db-b1ba-d64300c9c793}.TMContainer00000000000000000002.regtrans-ms
2008-04-24 17:00 . 2008-04-24 17:08 524,288 --ahs---- C:\Users\Patrick\NTUSER.DAT{3d4e88f1-6a70-11db-b1ba-d64300c9c793}.TMContainer00000000000000000001.regtrans-ms
2008-04-24 17:00 . 2008-04-27 17:02 262,144 --ah----- C:\Users\Patrick\ntuser.dat.LOG1
2008-04-24 17:00 . 2008-04-24 17:08 65,536 --ahs---- C:\Users\Patrick\NTUSER.DAT{3d4e88f1-6a70-11db-b1ba-d64300c9c793}.TM.blf
2008-04-24 17:00 . 2008-04-24 17:00 10 --a------ C:\Windows\System32\firstboot.lgl
2008-04-24 17:00 . 2008-04-24 17:00 0 --ah----- C:\Users\Patrick\ntuser.dat.LOG2
2008-04-24 16:55 . 2008-04-24 16:55 <DIR> dr------- C:\Windows\System32\config\systemprofile\Contacts
7 Datei(en), . 2,949,140 C:\ComboFix\Bytes
4 Datei(en), . 128,250 C:\ComboFix\Bytes
4 Datei(en), . 128,250 C:\ComboFix\Bytes
2 Datei(en), . 55,050 C:\ComboFix\Bytes
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-27 13:23 1,732 ----a-w C:\tvtpktfilter.dat
2008-04-26 13:20 --------- d-----w C:\Program Files\Windows Mail
2008-04-26 13:15 --------- d-----w C:\ProgramData\Microsoft Help
2008-04-26 13:10 --------- d-----w C:\Program Files\Microsoft SQL Server
2008-04-26 13:07 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys
2008-04-26 13:07 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys
2008-04-26 13:07 3,505,720 ----a-w C:\Windows\System32\ntkrnlpa.exe
2008-04-26 13:07 3,471,928 ----a-w C:\Windows\System32\ntoskrnl.exe
2008-04-26 13:07 24,064 ----a-w C:\Windows\System32\netcfg.exe
2008-04-26 13:07 22,016 ----a-w C:\Windows\System32\netiougc.exe
2008-04-26 13:07 216,632 ----a-w C:\Windows\system32\drivers\netio.sys
2008-04-26 13:07 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys
2008-04-26 13:07 17,464 ----a-w C:\Windows\system32\drivers\intelide.sys
2008-04-26 13:07 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
2008-04-26 13:07 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys
2008-04-26 13:07 109,624 ----a-w C:\Windows\system32\drivers\ataport.sys
2008-04-26 13:05 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-04-26 13:05 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-04-26 13:05 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
2008-04-26 13:05 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-04-26 13:05 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-04-26 13:01 826,368 ----a-w C:\Windows\System32\wininet.dll
2008-04-26 13:01 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-04-26 13:01 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-04-26 13:01 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-04-26 06:54 --------- d-----w C:\Program Files\ThinkVantage
2008-04-26 06:45 --------- d-----w C:\ProgramData\Symantec
2008-04-24 23:06 --------- d-----w C:\Program Files\Common Files\Lenovo
2008-04-24 22:05 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-24 18:24 --------- d-----w C:\Program Files\ThinkVantage Fingerprint Software
2008-04-24 18:13 --------- d-----w C:\Program Files\InterVideo
2008-04-24 18:11 --------- d-----w C:\ProgramData\UIB
2008-04-24 18:07 --------- d-----w C:\Program Files\Lenovo
2008-04-24 17:57 129,784 ------w C:\Windows\System32\PxAFS.DLL
2008-04-24 17:55 --------- d-----w C:\Program Files\Analog Devices
2008-04-24 17:52 --------- d-----w C:\ProgramData\Lenovo
2008-04-24 17:49 --------- d-----w C:\Program Files\PCDR5
2008-04-24 17:45 --------- d-----w C:\Program Files\Intel
2008-04-24 17:38 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-24 15:38 --------- d-----w C:\Program Files\Java
2008-04-24 15:31 --------- d-----w C:\Program Files\Norton Internet Security
2008-04-24 15:24 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-24 15:23 805 ----a-w C:\Windows\system32\drivers\SYMEVENT.INF
2008-04-24 15:23 123,952 ----a-w C:\Windows\system32\drivers\SYMEVENT.SYS
2008-04-24 15:23 10,740 ----a-w C:\Windows\system32\drivers\SYMEVENT.CAT
2008-04-24 15:23 --------- d-----w C:\Program Files\Symantec
2008-04-24 15:00 100 ----a-w C:\Windows\system32\drivers\Lenovo_7663_PJG.MRK
2008-04-24 14:56 --------- d-sh--w C:\ProgramData\Vorlagen
2008-04-24 14:56 --------- d-sh--w C:\ProgramData\Startmenü
2008-04-24 14:56 --------- d-sh--w C:\ProgramData\Favoriten
2008-04-24 14:56 --------- d-sh--w C:\ProgramData\Dokumente
2008-04-24 14:56 --------- d-sh--w C:\ProgramData\Anwendungsdaten
2008-04-24 14:56 --------- d-sh--w C:\Program Files\Gemeinsame Dateien
2008-03-23 15:15 974,336 ----a-w C:\Windows\System32\crypt32.dll
2008-03-23 15:14 29,184 ----a-w C:\Windows\system32\drivers\BTHUSB.SYS
2008-03-23 15:14 25,656 ----a-w C:\Windows\system32\drivers\msahci.sys
2008-03-23 15:14 220,160 ----a-w C:\Windows\system32\drivers\bthport.sys
2008-03-23 15:14 211,000 ----a-w C:\Windows\system32\drivers\volsnap.sys
2008-03-23 15:14 20,024 ------w C:\Windows\system32\drivers\viaide.sys
2008-03-23 15:14 19,456 ----a-w C:\Windows\system32\drivers\bthenum.sys
2008-03-23 15:14 19,000 ------w C:\Windows\system32\drivers\cmdide.sys
2008-03-23 15:14 181,760 ----a-w C:\Windows\System32\fsquirt.exe
2008-03-23 15:14 17,976 ------w C:\Windows\system32\drivers\amdide.sys
2008-03-23 15:14 17,464 ------w C:\Windows\system32\drivers\aliide.sys
2008-03-23 15:14 15,928 ------w C:\Windows\system32\drivers\pciide.sys
2008-03-23 15:14 --------- d-----w C:\Program Files\Windows Sidebar
2008-03-23 15:13 11,776 ----a-w C:\Windows\System32\sbunattend.exe
2008-03-23 15:12 84,992 ----a-w C:\Windows\system32\drivers\srvnet.sys
2008-03-23 15:12 58,368 ----a-w C:\Windows\system32\drivers\mrxsmb20.sys
2008-03-23 15:12 2,048 ----a-w C:\Windows\System32\tzres.dll
2008-03-23 15:12 130,048 ----a-w C:\Windows\system32\drivers\srv2.sys
2008-03-23 15:12 101,888 ----a-w C:\Windows\system32\drivers\mrxsmb.sys
2008-03-23 15:09 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
2008-03-23 15:08 750,080 ----a-w C:\Windows\System32\qmgr.dll
2008-03-23 15:06 53,760 ----a-w C:\Windows\system32\drivers\hdaudbus.sys
2008-03-23 15:06 13,312 ------w C:\Windows\system32\drivers\sffdisk.sys
2008-03-23 15:06 12,800 ------w C:\Windows\system32\drivers\sffp_sd.sys
2008-03-23 15:06 12,800 ------w C:\Windows\system32\drivers\sffp_mmc.sys
2008-03-23 15:05 86,016 ----a-w C:\Windows\System32\icfupgd.dll
2008-03-23 15:05 63,488 ----a-w C:\Windows\system32\drivers\mpsdrv.sys
2008-03-23 15:05 61,952 ----a-w C:\Windows\System32\cmifw.dll
2008-03-23 15:05 396,800 ----a-w C:\Windows\System32\MPSSVC.dll
2008-03-23 15:05 392,192 ----a-w C:\Windows\System32\FirewallAPI.dll
2008-03-23 15:05 374,456 ----a-w C:\Windows\System32\mcupdate_GenuineIntel.dll
2008-03-23 15:05 23,040 ----a-w C:\Windows\system32\drivers\tunnel.sys
2008-03-23 15:05 2,048 ----a-w C:\Windows\System32\msxml3r.dll
2008-03-23 15:05 178,688 ----a-w C:\Windows\System32\iphlpsvc.dll
2008-03-23 15:05 16,896 ----a-w C:\Windows\System32\wfapigp.dll
2008-03-23 15:05 15,360 ----a-w C:\Windows\system32\drivers\TUNMP.SYS
2008-03-23 15:05 1,191,936 ----a-w C:\Windows\System32\msxml3.dll
2008-03-23 15:03 5,120 ----a-w C:\Windows\System32\wmi.dll
2008-03-23 15:03 152,576 ----a-w C:\Windows\System32\imagehlp.dll
2008-03-23 15:03 12,800 ----a-w C:\Windows\system32\drivers\fs_rec.sys
2008-03-23 15:03 104,448 ----a-w C:\Windows\System32\DWWIN.EXE
2008-03-23 15:03 --------- d-----w C:\Program Files\Windows Defender
2008-03-23 15:02 74,752 ----a-w C:\Windows\system32\drivers\rasl2tp.sys
2008-03-23 15:02 60,928 ----a-w C:\Windows\system32\drivers\raspptp.sys
2008-03-23 15:02 500,224 ----a-w C:\Windows\System32\msdtcprx.dll
2008-03-23 15:02 49,664 ----a-w C:\Windows\System32\csrsrv.dll
2008-03-23 15:02 376,320 ----a-w C:\Windows\System32\winsrv.dll
.
(((((((((((((((((((((((((((( Autostart Punkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Hinweis* leere Eintrage & legitime Standardeintrage werden nicht angezeigt.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BF468356-BB7E-42D7-9F15-4F3B9BCFCED2}]
2008-02-19 13:05 784960 --a------ C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-03-23 17:13 1232896]
"WindowsWelcomeCenter"="oobefldr.dll" [2006-11-02 14:35 2159104 C:\Windows\System32\oobefldr.dll]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-03-23 17:03 1006264]
"TPFNF7"="C:\PROGRA~1\Lenovo\NPDIRECT\TPFNF7SP.exe" [2008-03-26 03:06 59680]
"PWMTRV"="C:\PROGRA~1\ThinkPad\UTILIT~1\PWMTR32V.DLL" [2008-01-11 02:20 558368]
"BLOG"="C:\PROGRA~1\ThinkPad\UTILIT~1\BTVLogEx.DLL" [2008-01-11 02:20 214576]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-11-21 18:08 820520]
"TPHOTKEY"="C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe" [2008-01-24 10:21 66928]
"TpShocks"="TpShocks.exe" [2007-11-22 16:09 181536 C:\Windows\System32\TpShocks.exe]
"EZEJMNAP"="C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2007-04-27 02:33 243248]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-07-27 09:57 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-07-27 09:57 8433664]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-07-27 09:57 81920]
"LenovoOobeOffers"="c:\SWTOOLS\LenovoWelcome\LenovoOobeOffers.exe" [2007-09-25 21:53 28672]
"TVT Scheduler Proxy"="C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2008-03-04 10:34 487424]
"DiskeeperSystray"="C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-11-15 17:21 217176]
"AwaySch"="C:\Program Files\Lenovo\AwayTask\AwaySch.EXE" [2006-11-07 12:51 91688]
"LPManager"="C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe" [2008-01-11 02:21 144728]
"AMSG"="C:\Program Files\ThinkVantage\AMSG\Amsg.exe" [2007-02-01 20:00 419376]
"RoxioDragToDisc"="C:\Program Files\Lenovo\Drag-to-Disc\DrgToDsc.exe" [2007-03-13 10:05 1116920]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42 144784]
"ACTray"="C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe" [2008-03-17 13:37 431392]
"ACWLIcon"="C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2008-03-17 13:37 128288]
"IaNvSrv"="C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe" [2007-10-24 03:02 33304]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 23:59 115816]
"MMReminderService"="C:\Program Files\Mindjet\MindManager 7\MMReminderService.exe" [2007-05-18 00:05 37392]
"LPMailChecker"="C:\PROGRA~1\THINKV~2\PrdCtr\LPMLCHK.exe" [2008-01-11 02:21 124248]
"cssauth"="C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" [2007-11-29 18:36 2872632]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2007-12-07 10:13 1282048]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"WinampAgent"="C:\Programme\Winamp\winampa.exe" [2008-04-01 20:49 36352]
C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 15:41:28 393216]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
BTTray.lnk - C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe [2007-03-29 14:11:50 719664]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2008-03-23 08:41:16 50688]
LenovoRegistration.lnk - C:\SWTOOLS\LenovoWelcome\LenovoRegistration.cmd [2007-10-04 21:41:21 166]
VPN Client.lnk - C:\Windows\Installer\{CCBAA1F7-E5E1-48B2-9ED9-A79C6A37CE78}\Icon3E5562ED7.ico [2008-04-26 08:26:34 6144]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
C:\Windows\system32\psqlpwd.dll 2007-08-14 15:54 89600 C:\Windows\System32\psqlpwd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{8A39DB58-28DD-4BA3-970A-BC1E6A43FFFE}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"TCP Query User{5BFBFD37-78F0-4B7A-BD03-DB0061B67C86}C:\\program files\\skype\\phone\\skype.exe"= UDP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"UDP Query User{05E6AF01-D3A5-4623-AF6D-9FB91D1AFC7B}C:\\program files\\skype\\phone\\skype.exe"= TCP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 iaNvStor;Intel(R) Turbo Memory Controller;C:\Windows\system32\DRIVERS\iaNvStor.sys [2007-10-02 12:53]
R0 Shockprf;Shockprf;C:\Windows\system32\DRIVERS\Apsx86.sys [2007-10-16 19:33]
R0 TPDIGIMN;TPDIGIMN;C:\Windows\system32\DRIVERS\ApsHM86.sys [2007-10-16 19:32]
R1 DLARTL_M;DLARTL_M;C:\Windows\system32\Drivers\DLARTL_M.SYS [2007-02-08 21:05]
R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20080423.002\IDSvix86.sys [2008-04-04 17:47]
R1 lenovo.smi;Lenovo System Interface Driver;C:\Windows\system32\DRIVERS\smiif32.sys [2006-08-30 12:04]
R1 TPPWRIF;TPPWRIF;C:\Windows\system32\drivers\Tppwr32v.sys [2008-01-11 02:20]
R1 tvtumon;tvtumon;C:\Windows\system32\DRIVERS\tvtumon.sys [2008-02-03 09:20]
R2 AEADIFilters;Andrea ADI Filters Service;C:\Windows\system32\AEADISRV.EXE [2007-02-06 00:44]
R2 BcmSqlStartupSvc;SQL Server-Startdienst für Business Contact Manager;"C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe" [2008-01-16 09:51]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
R2 smihlp2;SMI Helper Driver (smihlp2);C:\Program Files\Common Files\ThinkVantage Fingerprint Software\Drivers\smihlp.sys [2007-08-14 15:46]
R2 SQLWriter;SQL Server VSS Writer;"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 05:29]
R2 TPHKSVC;Anzeige am Bildschirm;C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe [2007-12-14 16:37]
R2 TVT Backup Protection Service;TVT Backup Protection Service;"C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe" [2007-12-05 17:32]
R2 TVT_UpdateMonitor;TVT Windows Update Monitor;C:\Program Files\Lenovo\Rescue and Recovery\UpdateMonitor.exe [2008-02-03 09:20]
R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2006-11-28 09:44]
R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2007-01-09 16:32]
R3 TcUsb;TC USB Kernel Driver;C:\Windows\system32\Drivers\tcusb.sys [2007-08-14 15:25]
R3 TVTI2C;Lenovo SM bus driver;C:\Windows\system32\DRIVERS\Tvti2c.sys [2007-05-22 16:59]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\b57nd60x.sys [2006-11-02 09:30]
S3 btwaudio;Bluetooth-Audiogerät;C:\Windows\system32\drivers\btwaudio.sys [2007-03-29 20:46]
S3 btwavdt;Bluetooth AVDT;C:\Windows\system32\drivers\btwavdt.sys [2007-02-27 07:20]
S3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys [2007-02-27 07:20]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);"c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a4fc450b-f8a0-11dc-b2fa-806e6f6e6963}]
\shell\AutoRun\command - E:\Launch.exe
*Newly Created Service* - COMHOST
.
Inhalt des "geplante Tasks" Ordners
"2008-04-27 14:06:01 C:\Windows\Tasks\Auf Updates für Windows Live Toolbar prüfen.job"
--------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:11, on 2008-04-27
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\conime.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe
C:\Program Files\Lenovo\NPDIRECT\tpfnf7sp.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
C:\Windows\System32\TpShocks.exe
C:\Program Files\ThinkPad\Utilities\EZEJMNAP.EXE
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
C:\Program Files\ThinkVantage\PrdCtr\LPMGR.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\ThinkVantage\AMSG\Amsg.exe
C:\Program Files\Lenovo\Drag-to-Disc\DrgToDsc.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\ThinkVantage\PrdCtr\LPMLCHK.EXE
C:\Program Files\Lenovo\Client Security Solution\cssauth.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Programme\Winamp\winampa.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Program Files\Lenovo\Client Security Solution\password_manager.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.live.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - c:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Password Manager Browser Helper Object - {BF468356-BB7E-42D7-9F15-4F3B9BCFCED2} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - c:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [TPFNF7] C:\PROGRA~1\Lenovo\NPDIRECT\TPFNF7SP.exe /r
O4 - HKLM\..\Run: [PWMTRV] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWMTR32V.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BTVLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LenovoOobeOffers] c:\SWTOOLS\LenovoWelcome\LenovoOobeOffers.exe /filePath="c:\swshare\firstrun.txt"
O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [AwaySch] C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe
O4 - HKLM\..\Run: [AMSG] C:\Program Files\ThinkVantage\AMSG\Amsg.exe /startup
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Lenovo\Drag-to-Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
O4 - HKLM\..\Run: [IaNvSrv] C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [MMReminderService] C:\Program Files\Mindjet\MindManager 7\MMReminderService.exe
O4 - HKLM\..\Run: [LPMailChecker] C:\PROGRA~1\THINKV~2\PrdCtr\LPMLCHK.exe
O4 - HKLM\..\Run: [cssauth] "C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" silent
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Programme\Winamp\winampa.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETZWERKDIENST')
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: LenovoRegistration.lnk = C:\SWTOOLS\LenovoWelcome\LenovoRegistration.cmd
O4 - Global Startup: VPN Client.lnk = ?
O8 - Extra context menu item: &Windows Live Search - res://c:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
O9 - Extra 'Tools' menuitem: Lenovo Password Manager... - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
O13 - Gopher Prefix:
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\Windows\system32\AEADISRV.EXE
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\Windows\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: IPS-Basisservice (IPSSVC) - Lenovo Group Limited - C:\Windows\system32\IPSSVC.EXE
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\program files\lenovo\system update\suservice.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\Windows\System32\TPHDEXLG.exe
O23 - Service: Anzeige am Bildschirm (TPHKSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
O23 - Service: TSS Core Service (TSSCoreService) - Lenovo - C:\Program Files\Lenovo\Client Security Solution\tvttcsd.exe
O23 - Service: TVT Backup Protection Service - Unknown owner - C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe
O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
O23 - Service: TVT Scheduler - Lenovo Group Limited - c:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
O23 - Service: tvtnetwk - Unknown owner - C:\Program Files\Lenovo\Rescue and Recovery\ADM\IUService.exe
O23 - Service: TVT Windows Update Monitor (TVT_UpdateMonitor) - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\UpdateMonitor.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 13617 bytes
Rorschach112
2008-04-28, 02:54
Looking good
1. Close any open browsers.
2. Open notepad and copy/paste the text in the quotebox below into it:
File::
E:\Launch.exe
DirLook::
C:\Windows\x
Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a4fc450b-f8a0-11dc-b2fa-806e6f6e6963}]
Driver::
Save this as CFScript.txt, in the same location as ComboFix.exe
http://i266.photobucket.com/albums/ii277/sUBs_/Combo-Do.gif
Refering to the picture above, drag CFScript into ComboFix.exe
When finished, it shall produce a log for you at "C:\ComboFix.txt"
Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Please download Malwarebytes' Anti-Malware from Here (http://www.besttechie.net/tools/mbam-setup.exe) or Here (http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html)
Double Click mbam-setup.exe to install the application.
Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select "Perform Full Scan", then click Scan. Check all the boxes and click Start Scan
The scan may take some time to finish,so please be patient.
When the scan is complete, click OK, then Show Results to view the results.
Make sure that everything is checked, and click Remove Selected.
When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
Also tell me how your PC is running
WalkerTXRanger
2008-04-29, 09:40
Hello one last time, I hope :)
This ist the mbam log:
Malwarebytes' Anti-Malware 1.11
Datenbank Version: 694
Scan Art: Komplett Scan (C:\|)
Objekte gescannt: 200635
Scan Dauer: 1 hour(s), 3 minute(s), 15 second(s)
Infizierte Speicher Prozesse: 0
Infizierte Speicher Module: 0
Infizierte Registrierungsschlüssel: 1
Infizierte Registrierungswerte: 0
Infizierte Datei Objekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 10
Infizierte Speicher Prozesse:
(Keine Malware Objekte gefunden)
Infizierte Speicher Module:
(Keine Malware Objekte gefunden)
Infizierte Registrierungsschlüssel:
HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
Infizierte Registrierungswerte:
(Keine Malware Objekte gefunden)
Infizierte Datei Objekte der Registrierung:
(Keine Malware Objekte gefunden)
Infizierte Verzeichnisse:
(Keine Malware Objekte gefunden)
Infizierte Dateien:
C:\_OTMoveIt\MovedFiles\04272008_163311\Users\Patrick\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WFTWBPYO\kriv[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\_OTMoveIt\MovedFiles\04272008_163311\Users\Patrick\AppData\Local\Temp\oxwgdxvg.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\_OTMoveIt\MovedFiles\04272008_163311\Users\Patrick\AppData\Local\Temp\tmp00015aeb (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\_OTMoveIt\MovedFiles\04272008_163311\Users\Patrick\AppData\Local\Temp\tmp00015caf (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\_OTMoveIt\MovedFiles\04272008_163311\Users\Patrick\AppData\Local\Temp\tmp00017686 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\_OTMoveIt\MovedFiles\04272008_163311\Users\Patrick\AppData\Local\Temp\tmp00018aa2 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\_OTMoveIt\MovedFiles\04272008_163311\Users\Patrick\AppData\Local\Temp\tmp0001ab3c (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\_OTMoveIt\MovedFiles\04272008_163311\Users\Patrick\AppData\Local\Temp\tmp000245d5 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\_OTMoveIt\MovedFiles\04272008_163311\Users\Patrick\AppData\Local\Temp\tmp00046ac3 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\_OTMoveIt\MovedFiles\04272008_163311\Users\Patrick\AppData\Local\Temp\tmp0004814f (Trojan.Vundo) -> Quarantined and deleted successfully.
My Laptop runs just fine again. The browsers don't open pop-ups / -unders etc anymore. Everything seems to be back to normal.
Thank you a lot for your great help! Couldn't have done it without you.
Rorschach112
2008-04-29, 15:10
Just need to see the ComboFix log then can send you on your way :)
WalkerTXRanger
2008-04-29, 17:52
Here you go :)
ComboFix 08-04-27.3 - Patrick 2008-04-28 23:22:14.2 - NTFSx86
Microsoft® Windows Vista™ Business 6.0.6000.0.1252.1.1031.18.1503 [GMT 2:00]
ausgeführt von:: C:\Users\Patrick\Desktop\ComboFix.exe
Command switches used :: C:\Users\Patrick\Desktop\CFScript.txt
* Neuer Wiederherstellungspunkt wurde erstellt
FILE ::
E:\Launch.exe
.
((((((((((((((((((((((( Dateien erstellt von 2008-03-28 bis 2008-04-28 ))))))))))))))))))))))))))))))
.
2008-04-27 18:21 . 2008-04-27 18:21 <DIR> d-------- C:\Users\All Users\TEMP
2008-04-27 18:21 . 2008-04-27 18:21 <DIR> d-------- C:\ProgramData\TEMP
2008-04-27 18:20 . 2008-04-27 18:23 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-04-27 18:20 . 2005-08-25 18:19 115,920 --a------ C:\Windows\System32\MSINET.OCX
2008-04-27 16:33 . 2008-04-27 16:33 <DIR> d-------- C:\_OTMoveIt
2008-04-27 15:46 . 2008-04-27 15:46 <DIR> d-------- C:\_SMA
2008-04-27 15:27 . 2008-04-27 15:27 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-27 13:17 . 2008-04-27 13:17 <DIR> d-------- C:\Windows\System32\Kaspersky Lab
2008-04-27 11:15 . 2008-04-27 11:29 <DIR> d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-04-27 11:15 . 2008-04-27 11:29 <DIR> d-------- C:\ProgramData\Spybot - Search & Destroy
2008-04-27 11:15 . 2008-04-27 11:15 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-27 01:13 . 2008-04-27 01:13 <DIR> d-------- C:\Program Files\TeXnicCenter
2008-04-27 01:07 . 2008-04-27 01:07 <DIR> d-------- C:\Users\Patrick\AppData\Roaming\MiKTeX
2008-04-27 00:51 . 2008-04-27 01:04 <DIR> d-------- C:\Program Files\MiKTeX 2.7
2008-04-26 15:14 . 2008-04-26 15:14 194,560 --a------ C:\Windows\System32\WebClnt.dll
2008-04-26 15:14 . 2008-04-26 15:14 110,080 --a------ C:\Windows\System32\drivers\mrxdav.sys
2008-04-26 15:13 . 2008-04-26 15:13 1,060,920 --a------ C:\Windows\System32\drivers\ntfs.sys
2008-04-26 15:06 . 2008-04-26 15:06 2,027,008 --a------ C:\Windows\System32\win32k.sys
2008-04-26 15:05 . 2008-04-26 15:05 4,247,552 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-04-26 15:05 . 2008-04-26 15:05 1,686,528 --a------ C:\Windows\System32\gameux.dll
2008-04-26 15:05 . 2008-04-26 15:05 296,448 --a------ C:\Windows\System32\gdi32.dll
2008-04-26 15:04 . 2008-04-26 15:04 558,080 --a------ C:\Windows\System32\oleaut32.dll
2008-04-26 15:03 . 2008-04-26 15:03 148,992 --a------ C:\Windows\System32\drivers\ks.sys
2008-04-26 15:03 . 2008-04-26 15:03 83,968 --a------ C:\Windows\System32\dnsrslvr.dll
2008-04-26 15:03 . 2008-04-26 15:03 24,576 --a------ C:\Windows\System32\dnscacheugc.exe
2008-04-26 14:59 . 2008-04-26 14:59 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-04-26 11:07 . 2008-04-28 20:20 27,525 --a------ C:\Users\Patrick\AppData\Roaming\nvModes.dat
2008-04-26 08:37 . 2008-04-26 08:37 1,712,984 --a------ C:\Windows\System32\wuaueng.dll
2008-04-26 08:37 . 2008-04-26 08:37 1,524,224 --a------ C:\Windows\System32\wucltux.dll
2008-04-26 08:37 . 2008-04-26 08:37 53,080 --a------ C:\Windows\System32\wuauclt.exe
2008-04-26 08:37 . 2008-04-26 08:37 43,352 --a------ C:\Windows\System32\wups2.dll
2008-04-26 08:36 . 2008-04-26 08:36 549,720 --a------ C:\Windows\System32\wuapi.dll
2008-04-26 08:36 . 2008-04-26 08:36 163,000 --a------ C:\Windows\System32\wuwebv.dll
2008-04-26 08:36 . 2008-04-26 08:36 80,896 --a------ C:\Windows\System32\wudriver.dll
2008-04-26 08:36 . 2008-04-26 08:36 33,624 --a------ C:\Windows\System32\wups.dll
2008-04-26 08:36 . 2008-04-26 08:36 31,232 --a------ C:\Windows\System32\wuapp.exe
2008-04-26 08:25 . 2008-04-26 08:25 <DIR> d-------- C:\Program Files\Common Files\Deterministic Networks
2008-04-26 08:25 . 2007-01-31 13:45 127,376 --a------ C:\Windows\System32\drivers\dne2000.sys
2008-04-26 08:25 . 2007-01-31 13:45 101,904 --a------ C:\Windows\System32\dneinobj.dll
2008-04-26 08:24 . 2008-04-26 08:24 <DIR> d-------- C:\Program Files\Cisco Systems
2008-04-26 08:24 . 2008-04-26 08:26 1,593 --a------ C:\Windows\VPNInstall.MIF
2008-04-25 17:08 . 2008-04-25 17:27 <DIR> d-------- C:\Installs
2008-04-25 16:40 . 2008-04-25 16:47 <DIR> d-------- C:\Lebenslauf
2008-04-25 16:33 . 2008-04-25 16:33 <DIR> d-------- C:\Users\Patrick\AppData\Roaming\GMX
2008-04-25 16:33 . 2008-04-25 16:33 <DIR> d-------- C:\Users\All Users\GMX
2008-04-25 16:33 . 2008-04-25 16:33 <DIR> d-------- C:\ProgramData\GMX
2008-04-25 16:33 . 2008-04-25 16:33 <DIR> d-------- C:\Program Files\GMX
2008-04-25 16:33 . 2008-04-01 12:54 90,112 --a------ C:\Windows\System32\UIGMXMON.DLL
2008-04-25 11:02 . 2008-04-25 11:02 <DIR> d-------- C:\Users\Patrick\AppData\Roaming\Leadertech
2008-04-25 10:59 . 2008-04-26 10:26 <DIR> d-------- C:\Users\Patrick\.freemind
2008-04-25 10:40 . 2008-04-25 10:40 <DIR> d-------- C:\Users\Patrick\AppData\Roaming\Talkback
2008-04-25 09:58 . 2008-04-25 09:59 <DIR> d-------- C:\Users\Patrick\AppData\Roaming\Thunderbird
2008-04-25 09:58 . 2008-04-25 09:58 <DIR> d-------- C:\Program Files\Mozilla Thunderbird
2008-04-25 09:47 . 2008-04-25 11:02 <DIR> d-------- C:\Program Files\FreeMind
2008-04-25 01:14 . 2008-04-28 17:47 <DIR> dr------- C:\MPICC
2008-04-25 01:06 . 2008-02-03 09:20 47,680 --a------ C:\Windows\System32\drivers\tvtumon.sys
2008-04-25 00:41 . 2008-04-25 00:43 <DIR> d-------- C:\Users\Patrick\AppData\Roaming\Winamp
2008-04-25 00:41 . 2008-04-25 00:42 <DIR> d-------- C:\Program Files\Winamp
2008-04-25 00:13 . 2008-04-28 20:25 <DIR> d-------- C:\Users\Patrick\AppData\Roaming\skypePM
2008-04-25 00:13 . 2008-04-25 00:13 32 --a------ C:\Users\All Users\ezsid.dat
2008-04-25 00:13 . 2008-04-25 00:13 32 --a------ C:\ProgramData\ezsid.dat
2008-04-25 00:11 . 2008-04-28 23:23 <DIR> d-------- C:\Users\Patrick\AppData\Roaming\Skype
2008-04-25 00:10 . 2008-04-25 00:10 <DIR> d-------- C:\Users\All Users\Skype
2008-04-25 00:10 . 2008-04-25 00:10 <DIR> d-------- C:\ProgramData\Skype
2008-04-25 00:10 . 2008-04-25 00:10 <DIR> d-------- C:\Program Files\Skype
2008-04-25 00:10 . 2008-04-25 00:10 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-04-25 00:07 . 2008-04-28 20:20 <DIR> d-------- C:\Users\Patrick\AppData\Roaming\OpenOffice.org2
2008-04-24 23:56 . 2008-04-25 00:16 <DIR> d-------- C:\Program Files\Mozilla Firefox 3 Beta 5
2008-04-24 23:53 . 2008-04-28 20:19 2,080 --a------ C:\Windows\System32\ICAutoUpdate.log.bak
2008-04-24 23:46 . 2008-04-26 08:30 213,757,563 --a------ C:\sysiclog.txt.bak
2008-04-24 20:11 . 2008-04-24 20:11 <DIR> d-------- C:\Program Files\Common Files\ThinkVantage Fingerprint Software
2008-04-24 20:07 . 2008-04-24 20:07 33,536 --a------ C:\Windows\System32\drivers\tvtfilter.sys
2008-04-24 19:51 . 2008-04-24 19:51 390,144 --a------ C:\Windows\System32\wlangpui.dll
2008-04-24 19:51 . 2008-04-24 19:51 225,792 --a------ C:\Windows\System32\dot3gpui.dll
2008-04-24 19:51 . 2008-04-24 19:51 223,526 --a------ C:\Windows\System32\onex.tmf
2008-04-24 19:51 . 2008-04-24 19:51 162,816 --a------ C:\Windows\System32\onex.dll
2008-04-24 19:51 . 2008-04-24 19:51 146,944 --a------ C:\Windows\System32\dot3svc.dll
2008-04-24 19:51 . 2008-04-24 19:51 141,824 --a------ C:\Windows\System32\dot3ui.dll
2008-04-24 19:51 . 2008-04-24 19:51 72,192 --a------ C:\Windows\System32\dot3msm.dll
2008-04-24 19:51 . 2008-04-24 19:51 45,568 --a------ C:\Windows\System32\dot3dlg.dll
2008-04-24 19:51 . 2008-04-24 19:51 26,112 --a------ C:\Windows\System32\dot3api.dll
2008-04-24 19:50 . 2008-04-24 19:51 199,680 --a------ C:\Windows\System32\wlanui.dll
2008-04-24 19:48 . 2008-04-24 19:48 54,784 --a------ C:\Windows\System32\drivers\i8042prt.sys
2008-04-24 19:48 . 2008-04-24 19:48 35,512 --a------ C:\Windows\System32\drivers\kbdclass.sys
2008-04-24 19:46 . 2008-04-24 19:46 <DIR> d-------- C:\Users\All Users\Intel
2008-04-24 19:46 . 2008-04-24 19:46 <DIR> d-------- C:\ProgramData\Intel
2008-04-24 19:46 . 2008-04-24 19:46 <DIR> d-------- C:\Program Files\Cisco
2008-04-24 19:41 . 2008-04-24 19:41 188 --a------ C:\Windows\x
2008-04-24 18:34 . 2008-04-28 10:32 <DIR> d-------- C:\Uni
2008-04-24 18:21 . 2008-04-25 11:36 <DIR> d-------- C:\MP3s
2008-04-24 17:55 . 2008-04-24 17:55 47 --a------ C:\Windows\System32\drivers\IBM_7663_PJG.MRK
2008-04-24 17:38 . 2008-04-24 17:38 <DIR> d-------- C:\Program Files\OpenOffice.org 2.4
2008-04-24 17:29 . 2008-04-24 17:29 <DIR> d-------- C:\Users\All Users\Mindjet
2008-04-24 17:29 . 2008-04-24 17:29 <DIR> d-------- C:\ProgramData\Mindjet
2008-04-24 17:29 . 2008-04-24 17:29 <DIR> d-------- C:\Program Files\Mindjet
2008-04-24 17:29 . 2004-12-07 07:11 258,352 --a------ C:\Windows\System32\unicows.dll
2008-04-24 17:29 . 2006-01-30 09:32 5,632 --a------ C:\Windows\System32\pxc25pm.dll
2008-04-24 17:28 . 2008-04-24 17:28 16 --a------ C:\Windows\System32\coh.cache
2008-04-24 17:18 . 2008-04-24 17:18 0 --a------ C:\Windows\nsreg.dat
2008-04-24 17:04 . 2008-04-24 23:48 <DIR> d-------- C:\Users\Patrick\AppData\Roaming\Lenovo
2008-04-24 17:00 . 2006-11-02 15:04 <DIR> dr------- C:\Users\Patrick\Videos
2008-04-24 17:00 . 2008-04-24 17:02 <DIR> dr------- C:\Users\Patrick\Searches
2008-04-24 17:00 . 2006-11-02 15:04 <DIR> dr------- C:\Users\Patrick\Saved Games
2008-04-24 17:00 . 2006-11-02 15:04 <DIR> dr------- C:\Users\Patrick\Pictures
2008-04-24 17:00 . 2006-11-02 15:04 <DIR> dr------- C:\Users\Patrick\Music
2008-04-24 17:00 . 2008-04-24 17:02 <DIR> dr------- C:\Users\Patrick\Links
2008-04-24 17:00 . 2008-04-27 20:41 <DIR> dr------- C:\Users\Patrick\Downloads
2008-04-24 17:00 . 2008-04-25 00:02 <DIR> dr------- C:\Users\Patrick\Documents
2008-04-24 17:00 . 2006-11-02 15:04 <DIR> dr------- C:\Users\Patrick\Contacts
2008-04-24 17:00 . 2006-11-02 15:04 <DIR> d--h----- C:\Users\Patrick\AppData
2008-04-24 17:00 . 2008-04-26 08:25 <DIR> d-------- C:\Users\Patrick
2008-04-24 17:00 . 2008-04-24 17:00 <DIR> d-------- C:\Program Files\Windows Live Toolbar
2008-04-24 17:00 . 2008-04-24 17:08 524,288 --ahs---- C:\Users\Patrick\NTUSER.DAT{3d4e88f1-6a70-11db-b1ba-d64300c9c793}.TMContainer00000000000000000002.regtrans-ms
2008-04-24 17:00 . 2008-04-24 17:08 524,288 --ahs---- C:\Users\Patrick\NTUSER.DAT{3d4e88f1-6a70-11db-b1ba-d64300c9c793}.TMContainer00000000000000000001.regtrans-ms
2008-04-24 17:00 . 2008-04-28 23:23 262,144 --ah----- C:\Users\Patrick\ntuser.dat.LOG1
2008-04-24 17:00 . 2008-04-24 17:08 65,536 --ahs---- C:\Users\Patrick\NTUSER.DAT{3d4e88f1-6a70-11db-b1ba-d64300c9c793}.TM.blf
2008-04-24 17:00 . 2008-04-24 17:00 10 --a------ C:\Windows\System32\firstboot.lgl
2008-04-24 17:00 . 2008-04-24 17:00 0 --ah----- C:\Users\Patrick\ntuser.dat.LOG2
2008-04-24 16:55 . 2008-04-24 16:55 <DIR> dr------- C:\Windows\System32\config\systemprofile\Contacts
7 Datei(en), . 3,473,428 C:\ComboFix\Bytes
4 Datei(en), . 128,250 C:\ComboFix\Bytes
4 Datei(en), . 128,250 C:\ComboFix\Bytes
2 Datei(en), . 55,050 C:\ComboFix\Bytes
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-27 13:23 1,732 ----a-w C:\tvtpktfilter.dat
2008-04-26 13:20 --------- d-----w C:\Program Files\Windows Mail
2008-04-26 13:15 --------- d-----w C:\ProgramData\Microsoft Help
2008-04-26 13:10 --------- d-----w C:\Program Files\Microsoft SQL Server
2008-04-26 13:07 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys
2008-04-26 13:07 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys
2008-04-26 13:07 3,505,720 ----a-w C:\Windows\System32\ntkrnlpa.exe
2008-04-26 13:07 3,471,928 ----a-w C:\Windows\System32\ntoskrnl.exe
2008-04-26 13:07 24,064 ----a-w C:\Windows\System32\netcfg.exe
2008-04-26 13:07 22,016 ----a-w C:\Windows\System32\netiougc.exe
2008-04-26 13:07 216,632 ----a-w C:\Windows\system32\drivers\netio.sys
2008-04-26 13:07 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys
2008-04-26 13:07 17,464 ----a-w C:\Windows\system32\drivers\intelide.sys
2008-04-26 13:07 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
2008-04-26 13:07 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys
2008-04-26 13:07 109,624 ----a-w C:\Windows\system32\drivers\ataport.sys
2008-04-26 13:05 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-04-26 13:05 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-04-26 13:05 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
2008-04-26 13:05 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-04-26 13:05 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-04-26 13:01 826,368 ----a-w C:\Windows\System32\wininet.dll
2008-04-26 13:01 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-04-26 13:01 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-04-26 13:01 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-04-26 06:54 --------- d-----w C:\Program Files\ThinkVantage
2008-04-26 06:45 --------- d-----w C:\ProgramData\Symantec
2008-04-24 23:06 --------- d-----w C:\Program Files\Common Files\Lenovo
2008-04-24 22:05 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-24 18:24 --------- d-----w C:\Program Files\ThinkVantage Fingerprint Software
2008-04-24 18:13 --------- d-----w C:\Program Files\InterVideo
2008-04-24 18:11 --------- d-----w C:\ProgramData\UIB
2008-04-24 18:07 --------- d-----w C:\Program Files\Lenovo
2008-04-24 17:57 129,784 ------w C:\Windows\System32\PxAFS.DLL
2008-04-24 17:55 --------- d-----w C:\Program Files\Analog Devices
2008-04-24 17:52 --------- d-----w C:\ProgramData\Lenovo
2008-04-24 17:49 --------- d-----w C:\Program Files\PCDR5
2008-04-24 17:45 --------- d-----w C:\Program Files\Intel
2008-04-24 17:38 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-24 15:38 --------- d-----w C:\Program Files\Java
2008-04-24 15:31 --------- d-----w C:\Program Files\Norton Internet Security
2008-04-24 15:24 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-24 15:23 805 ----a-w C:\Windows\system32\drivers\SYMEVENT.INF
2008-04-24 15:23 123,952 ----a-w C:\Windows\system32\drivers\SYMEVENT.SYS
2008-04-24 15:23 10,740 ----a-w C:\Windows\system32\drivers\SYMEVENT.CAT
2008-04-24 15:23 --------- d-----w C:\Program Files\Symantec
2008-04-24 15:00 100 ----a-w C:\Windows\system32\drivers\Lenovo_7663_PJG.MRK
2008-04-24 14:56 --------- d-sh--w C:\ProgramData\Vorlagen
2008-04-24 14:56 --------- d-sh--w C:\ProgramData\Startmenü
2008-04-24 14:56 --------- d-sh--w C:\ProgramData\Favoriten
2008-04-24 14:56 --------- d-sh--w C:\ProgramData\Dokumente
2008-04-24 14:56 --------- d-sh--w C:\ProgramData\Anwendungsdaten
2008-04-24 14:56 --------- d-sh--w C:\Program Files\Gemeinsame Dateien
2008-03-23 15:15 974,336 ----a-w C:\Windows\System32\crypt32.dll
2008-03-23 15:14 29,184 ----a-w C:\Windows\system32\drivers\BTHUSB.SYS
2008-03-23 15:14 25,656 ----a-w C:\Windows\system32\drivers\msahci.sys
2008-03-23 15:14 220,160 ----a-w C:\Windows\system32\drivers\bthport.sys
2008-03-23 15:14 211,000 ----a-w C:\Windows\system32\drivers\volsnap.sys
2008-03-23 15:14 20,024 ------w C:\Windows\system32\drivers\viaide.sys
2008-03-23 15:14 19,456 ----a-w C:\Windows\system32\drivers\bthenum.sys
2008-03-23 15:14 19,000 ------w C:\Windows\system32\drivers\cmdide.sys
2008-03-23 15:14 181,760 ----a-w C:\Windows\System32\fsquirt.exe
2008-03-23 15:14 17,976 ------w C:\Windows\system32\drivers\amdide.sys
2008-03-23 15:14 17,464 ------w C:\Windows\system32\drivers\aliide.sys
2008-03-23 15:14 15,928 ------w C:\Windows\system32\drivers\pciide.sys
2008-03-23 15:14 --------- d-----w C:\Program Files\Windows Sidebar
2008-03-23 15:13 11,776 ----a-w C:\Windows\System32\sbunattend.exe
2008-03-23 15:12 84,992 ----a-w C:\Windows\system32\drivers\srvnet.sys
2008-03-23 15:12 58,368 ----a-w C:\Windows\system32\drivers\mrxsmb20.sys
2008-03-23 15:12 2,048 ----a-w C:\Windows\System32\tzres.dll
2008-03-23 15:12 130,048 ----a-w C:\Windows\system32\drivers\srv2.sys
2008-03-23 15:12 101,888 ----a-w C:\Windows\system32\drivers\mrxsmb.sys
2008-03-23 15:09 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
2008-03-23 15:08 750,080 ----a-w C:\Windows\System32\qmgr.dll
2008-03-23 15:06 53,760 ----a-w C:\Windows\system32\drivers\hdaudbus.sys
2008-03-23 15:06 13,312 ------w C:\Windows\system32\drivers\sffdisk.sys
2008-03-23 15:06 12,800 ------w C:\Windows\system32\drivers\sffp_sd.sys
2008-03-23 15:06 12,800 ------w C:\Windows\system32\drivers\sffp_mmc.sys
2008-03-23 15:05 86,016 ----a-w C:\Windows\System32\icfupgd.dll
2008-03-23 15:05 63,488 ----a-w C:\Windows\system32\drivers\mpsdrv.sys
2008-03-23 15:05 61,952 ----a-w C:\Windows\System32\cmifw.dll
2008-03-23 15:05 396,800 ----a-w C:\Windows\System32\MPSSVC.dll
2008-03-23 15:05 392,192 ----a-w C:\Windows\System32\FirewallAPI.dll
2008-03-23 15:05 374,456 ----a-w C:\Windows\System32\mcupdate_GenuineIntel.dll
2008-03-23 15:05 23,040 ----a-w C:\Windows\system32\drivers\tunnel.sys
2008-03-23 15:05 2,048 ----a-w C:\Windows\System32\msxml3r.dll
2008-03-23 15:05 178,688 ----a-w C:\Windows\System32\iphlpsvc.dll
2008-03-23 15:05 16,896 ----a-w C:\Windows\System32\wfapigp.dll
2008-03-23 15:05 15,360 ----a-w C:\Windows\system32\drivers\TUNMP.SYS
2008-03-23 15:05 1,191,936 ----a-w C:\Windows\System32\msxml3.dll
2008-03-23 15:03 5,120 ----a-w C:\Windows\System32\wmi.dll
2008-03-23 15:03 152,576 ----a-w C:\Windows\System32\imagehlp.dll
2008-03-23 15:03 12,800 ----a-w C:\Windows\system32\drivers\fs_rec.sys
2008-03-23 15:03 104,448 ----a-w C:\Windows\System32\DWWIN.EXE
2008-03-23 15:03 --------- d-----w C:\Program Files\Windows Defender
2008-03-23 15:02 74,752 ----a-w C:\Windows\system32\drivers\rasl2tp.sys
2008-03-23 15:02 60,928 ----a-w C:\Windows\system32\drivers\raspptp.sys
2008-03-23 15:02 500,224 ----a-w C:\Windows\System32\msdtcprx.dll
2008-03-23 15:02 49,664 ----a-w C:\Windows\System32\csrsrv.dll
2008-03-23 15:02 376,320 ----a-w C:\Windows\System32\winsrv.dll
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\Windows\x ----
C:\Windows\x\
((((((((((((((((((((((((((((( snapshot@2008-04-27_17.04.17.25 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-26 13:00:48 1,257,472 ----a-w C:\Windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
+ 2008-04-27 15:34:59 1,265,664 ----a-w C:\Windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
- 2008-04-26 13:00:49 1,224,704 ----a-w C:\Windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
+ 2008-04-27 15:34:59 1,232,896 ----a-w C:\Windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
+ 2008-04-27 15:35:08 61,440 ----a-w C:\Windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_990d8bcd\CustomMarshalers.dll
+ 2008-04-27 15:35:32 118,784 ----a-w C:\Windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_b61164fe\CustomMarshalers.dll
+ 2008-04-27 16:05:03 8,908,800 ----a-w C:\Windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_2f8cf300\mscorlib.dll
+ 2008-04-27 15:35:25 3,391,488 ----a-w C:\Windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_f6a1eb32\mscorlib.dll
+ 2008-04-27 15:35:22 1,470,464 ----a-w C:\Windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_6285ba7c\System.Design.dll
+ 2008-04-27 16:04:56 3,395,584 ----a-w C:\Windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_c4fb35a2\System.Design.dll
+ 2008-04-27 15:35:09 90,112 ----a-w C:\Windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_7afa4606\System.Drawing.Design.dll
+ 2008-04-27 16:04:39 192,512 ----a-w C:\Windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_bcef0bec\System.Drawing.Design.dll
+ 2008-04-27 15:35:23 835,584 ----a-w C:\Windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_27b26e49\System.Drawing.dll
+ 2008-04-27 16:04:59 2,244,608 ----a-w C:\Windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_34771d7f\System.Drawing.dll
+ 2008-04-27 16:04:48 7,884,800 ----a-w C:\Windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_837c0fe0\System.Windows.Forms.dll
+ 2008-04-27 15:35:14 3,018,752 ----a-w C:\Windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_a55d4a65\System.Windows.Forms.dll
+ 2008-04-27 16:04:52 5,513,216 ----a-w C:\Windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_1fd1a873\System.Xml.dll
+ 2008-04-27 15:35:18 2,088,960 ----a-w C:\Windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_5837028e\System.Xml.dll
+ 2008-04-27 15:35:31 4,788,224 ----a-w C:\Windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_4ee31964\System.dll
+ 2008-04-27 15:35:07 1,966,080 ----a-w C:\Windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_b9993d57\System.dll
- 2008-04-27 15:00:49 67,584 --s-a-w C:\Windows\bootstat.dat
+ 2008-04-28 18:19:05 67,584 --s-a-w C:\Windows\bootstat.dat
+ 2008-04-27 15:35:13 32,768 ----a-r C:\Windows\Installer\{C523D256-313D-4866-B36A-F3DE528246EF}\icon.exe
- 2004-07-14 23:49:16 258,048 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2007-04-13 19:30:52 258,048 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
- 2004-07-14 23:49:22 32,768 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
+ 2007-04-13 19:30:52 32,768 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
- 2004-07-14 22:32:22 81,920 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
+ 2007-04-13 18:57:52 81,920 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
- 2003-02-20 18:09:14 86,016 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
+ 2007-04-13 18:57:58 86,016 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
- 2004-07-14 22:25:06 315,392 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
+ 2007-04-13 18:56:30 315,392 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
- 2004-07-14 22:33:04 102,400 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
+ 2007-04-13 18:58:00 102,400 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
- 2004-07-15 12:29:02 2,138,112 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2007-04-13 18:50:46 2,142,208 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
- 2003-02-20 18:09:18 77,824 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
+ 2007-04-13 18:58:02 77,824 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
- 2004-07-14 22:26:52 2,510,848 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
+ 2007-04-13 18:57:00 2,523,136 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
- 2004-07-14 22:28:34 2,502,656 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2007-04-13 18:57:28 2,514,944 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
- 2004-08-10 14:20:00 106,496 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe
+ 2007-01-15 14:11:26 73,728 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe
+ 2004-07-14 23:49:16 258,048 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\SHADOW4308\_aspnet_isapi.dll
+ 2004-07-14 22:32:22 81,920 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\SHADOW4308\_CORPerfMonExt.dll
+ 2004-07-14 22:24:30 282,624 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\SHADOW4308\_fusion.dll
+ 2004-07-14 22:25:06 315,392 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\SHADOW4308\_mscorjit.dll
+ 2004-07-15 12:29:02 2,138,112 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\SHADOW4308\_mscorlib.dll
+ 2003-02-20 18:09:18 77,824 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\SHADOW4308\_mscorsn.dll
+ 2004-07-14 22:26:52 2,510,848 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\SHADOW4308\_mscorsvr.dll
+ 2004-07-14 22:28:34 2,502,656 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\SHADOW4308\_mscorwks.dll
+ 2003-02-21 03:42:22 348,160 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\SHADOW4308\_msvcr71.dll
+ 2004-07-14 22:34:50 94,208 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\SHADOW4308\_PerfCounter.dll
- 2004-07-15 12:31:16 1,224,704 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\System.dll
+ 2007-04-13 19:35:38 1,232,896 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\System.dll
- 2004-07-15 12:29:00 1,257,472 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
+ 2007-04-13 19:35:46 1,265,664 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
+ 2008-04-28 18:19:06 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-04-28 18:19:06 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2008-04-27 15:01:57 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-04-28 18:21:21 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
- 2008-04-27 15:01:57 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-04-28 18:21:13 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-04-28 18:21:13 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2008-04-27 13:46:38 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-04-28 13:57:24 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-04-27 13:46:38 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-04-28 13:57:24 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-04-27 13:46:38 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-04-28 13:57:24 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-04-27 14:57:12 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
+ 2008-04-28 21:22:08 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
+ 2008-04-28 21:22:08 262,144 ---ha-w C:\Windows\System32\config\systemprofile\ntuser.dat.LOG1
- 2007-05-08 13:03:04 1,275,392 ----a-w C:\Windows\System32\msxml4.dll
+ 2007-08-24 16:08:24 1,275,392 ----a-w C:\Windows\System32\msxml4.dll
+ 2008-04-28 13:04:43 2,456 ----a-w C:\Windows\System32\networklist\icons\{FC3C5758-222D-4F1D-92BC-023FB7B47029}_24.bin
+ 2008-04-28 13:04:43 4,280 ----a-w C:\Windows\System32\networklist\icons\{FC3C5758-222D-4F1D-92BC-023FB7B47029}_32.bin
+ 2008-04-28 13:04:43 9,560 ----a-w C:\Windows\System32\networklist\icons\{FC3C5758-222D-4F1D-92BC-023FB7B47029}_48.bin
- 2008-04-27 09:46:48 6,291,456 ----a-w C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2008-04-27 19:21:07 6,291,456 ----a-w C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT
- 2008-04-27 14:38:53 3,740 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1748752477-3087473287-3414825192-1005_UserData.bin
+ 2008-04-28 18:21:41 4,184 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1748752477-3087473287-3414825192-1005_UserData.bin
- 2008-04-27 14:38:53 73,946 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-04-28 18:21:40 74,510 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-04-27 14:38:48 45,764 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-04-28 18:21:37 48,448 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-04-27 19:20:23 1,744,384 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\apds.dll
+ 2008-04-27 19:20:25 222,208 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\apircl.dll
+ 2008-04-27 19:20:23 199,168 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\apss.dll
+ 2008-04-27 19:20:24 534,528 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\CbsCore.dll
+ 2008-04-27 19:20:24 22,016 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\CbsMsg.dll
+ 2008-04-27 19:20:24 119,808 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\cmiadapter.dll
+ 2008-04-27 19:20:25 271,360 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\cmitrust.dll
+ 2008-04-27 19:20:26 2,032,640 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\cmiv2.dll
+ 2008-04-27 19:20:25 238,592 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\CntrtextInstaller.dll
+ 2008-04-27 19:20:23 258,560 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\dpx.dll
+ 2008-04-27 19:20:26 99,840 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\DrUpdate.dll
+ 2008-04-27 19:20:25 246,784 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\drvstore.dll
+ 2008-04-27 19:20:24 263,168 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\esscli.dll
+ 2008-04-27 19:20:24 614,400 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\fastprox.dll
+ 2008-04-27 19:20:24 100,352 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\helpcins.dll
+ 2008-04-27 19:20:25 222,720 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\locdrv.dll
+ 2008-04-27 19:20:27 191,488 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\mofd.dll
+ 2008-04-27 19:20:25 102,400 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\mofinstall.dll
+ 2008-04-27 19:20:24 305,152 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\msdelta.dll
+ 2008-04-27 19:20:24 35,328 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\mspatcha.dll
+ 2008-04-27 19:20:25 146,432 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\OEMHelpIns.dll
+ 2008-04-27 19:20:25 130,560 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\PkgMgr.exe
+ 2008-04-27 19:20:24 118,272 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\poqexec.exe
+ 2008-04-27 19:20:27 264,704 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\repdrvfs.dll
+ 2008-04-27 19:20:23 126,464 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\rescinst.dll
+ 2008-04-27 19:20:25 704,512 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\smiengine.dll
+ 2008-04-27 19:20:24 139,264 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\SmiInstaller.dll
+ 2008-04-27 19:20:25 116,736 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\smipi.dll
+ 2008-04-27 19:20:27 357,888 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\wbemcomn.dll
+ 2008-04-27 19:20:27 742,912 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\wbemcore.dll
+ 2008-04-27 19:20:26 30,208 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\wbemprox.dll
+ 2008-04-27 19:20:26 1,832,448 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\wcp.dll
+ 2008-04-27 19:20:25 218,624 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\wdscore.dll
+ 2008-04-27 19:20:24 83,968 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\wmiutils.dll
+ 2008-04-27 19:20:26 51,712 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\wrpint.dll
+ 2008-04-27 19:20:26 183,296 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\xmllite.dll
+ 2008-04-27 15:35:13 1,275,392 ----a-w C:\Windows\winsxs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9849.0_none_b7e911727b2899b7\msxml4.dll
.
-- Snapshot reset to current date --
.
(((((((((((((((((((((((((((( Autostart Punkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Hinweis* leere Eintrage & legitime Standardeintrage werden nicht angezeigt.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BF468356-BB7E-42D7-9F15-4F3B9BCFCED2}]
2008-02-19 13:05 784960 --a------ C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-03-23 17:13 1232896]
"WindowsWelcomeCenter"="oobefldr.dll" [2006-11-02 14:35 2159104 C:\Windows\System32\oobefldr.dll]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-03-23 17:03 1006264]
"TPFNF7"="C:\PROGRA~1\Lenovo\NPDIRECT\TPFNF7SP.exe" [2008-03-26 03:06 59680]
"PWMTRV"="C:\PROGRA~1\ThinkPad\UTILIT~1\PWMTR32V.DLL" [2008-01-11 02:20 558368]
"BLOG"="C:\PROGRA~1\ThinkPad\UTILIT~1\BTVLogEx.DLL" [2008-01-11 02:20 214576]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-11-21 18:08 820520]
"TPHOTKEY"="C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe" [2008-01-24 10:21 66928]
"TpShocks"="TpShocks.exe" [2007-11-22 16:09 181536 C:\Windows\System32\TpShocks.exe]
"EZEJMNAP"="C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2007-04-27 02:33 243248]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-07-27 09:57 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-07-27 09:57 8433664]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-07-27 09:57 81920]
"LenovoOobeOffers"="c:\SWTOOLS\LenovoWelcome\LenovoOobeOffers.exe" [2007-09-25 21:53 28672]
"TVT Scheduler Proxy"="C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2008-03-04 10:34 487424]
"DiskeeperSystray"="C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-11-15 17:21 217176]
"AwaySch"="C:\Program Files\Lenovo\AwayTask\AwaySch.EXE" [2006-11-07 12:51 91688]
"LPManager"="C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe" [2008-01-11 02:21 144728]
"AMSG"="C:\Program Files\ThinkVantage\AMSG\Amsg.exe" [2007-02-01 20:00 419376]
"RoxioDragToDisc"="C:\Program Files\Lenovo\Drag-to-Disc\DrgToDsc.exe" [2007-03-13 10:05 1116920]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42 144784]
"ACTray"="C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe" [2008-03-17 13:37 431392]
"ACWLIcon"="C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2008-03-17 13:37 128288]
"IaNvSrv"="C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe" [2007-10-24 03:02 33304]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 23:59 115816]
"MMReminderService"="C:\Program Files\Mindjet\MindManager 7\MMReminderService.exe" [2007-05-18 00:05 37392]
"LPMailChecker"="C:\PROGRA~1\THINKV~2\PrdCtr\LPMLCHK.exe" [2008-01-11 02:21 124248]
"cssauth"="C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" [2007-11-29 18:36 2872632]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2007-12-07 10:13 1282048]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"WinampAgent"="C:\Programme\Winamp\winampa.exe" [2008-04-01 20:49 36352]
C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 15:41:28 393216]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
BTTray.lnk - C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe [2007-03-29 14:11:50 719664]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2008-03-23 08:41:16 50688]
LenovoRegistration.lnk - C:\SWTOOLS\LenovoWelcome\LenovoRegistration.cmd [2007-10-04 21:41:21 166]
VPN Client.lnk - C:\Windows\Installer\{CCBAA1F7-E5E1-48B2-9ED9-A79C6A37CE78}\Icon3E5562ED7.ico [2008-04-26 08:26:34 6144]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
C:\Windows\system32\psqlpwd.dll 2007-08-14 15:54 89600 C:\Windows\System32\psqlpwd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{8A39DB58-28DD-4BA3-970A-BC1E6A43FFFE}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"TCP Query User{5BFBFD37-78F0-4B7A-BD03-DB0061B67C86}C:\\program files\\skype\\phone\\skype.exe"= UDP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"UDP Query User{05E6AF01-D3A5-4623-AF6D-9FB91D1AFC7B}C:\\program files\\skype\\phone\\skype.exe"= TCP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
R0 iaNvStor;Intel(R) Turbo Memory Controller;C:\Windows\system32\DRIVERS\iaNvStor.sys [2007-10-02 12:53]
R0 Shockprf;Shockprf;C:\Windows\system32\DRIVERS\Apsx86.sys [2007-10-16 19:33]
R0 TPDIGIMN;TPDIGIMN;C:\Windows\system32\DRIVERS\ApsHM86.sys [2007-10-16 19:32]
R1 DLARTL_M;DLARTL_M;C:\Windows\system32\Drivers\DLARTL_M.SYS [2007-02-08 21:05]
R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20080423.002\IDSvix86.sys [2008-04-04 17:47]
R1 lenovo.smi;Lenovo System Interface Driver;C:\Windows\system32\DRIVERS\smiif32.sys [2006-08-30 12:04]
R1 TPPWRIF;TPPWRIF;C:\Windows\system32\drivers\Tppwr32v.sys [2008-01-11 02:20]
R1 tvtumon;tvtumon;C:\Windows\system32\DRIVERS\tvtumon.sys [2008-02-03 09:20]
R2 AEADIFilters;Andrea ADI Filters Service;C:\Windows\system32\AEADISRV.EXE [2007-02-06 00:44]
R2 BcmSqlStartupSvc;SQL Server-Startdienst für Business Contact Manager;"C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe" [2008-01-16 09:51]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
R2 smihlp2;SMI Helper Driver (smihlp2);C:\Program Files\Common Files\ThinkVantage Fingerprint Software\Drivers\smihlp.sys [2007-08-14 15:46]
R2 SQLWriter;SQL Server VSS Writer;"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 05:29]
R2 TPHKSVC;Anzeige am Bildschirm;C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe [2007-12-14 16:37]
R2 TVT Backup Protection Service;TVT Backup Protection Service;"C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe" [2007-12-05 17:32]
R2 TVT_UpdateMonitor;TVT Windows Update Monitor;C:\Program Files\Lenovo\Rescue and Recovery\UpdateMonitor.exe [2008-02-03 09:20]
R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2006-11-28 09:44]
R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2007-01-09 16:32]
R3 TcUsb;TC USB Kernel Driver;C:\Windows\system32\Drivers\tcusb.sys [2007-08-14 15:25]
R3 TVTI2C;Lenovo SM bus driver;C:\Windows\system32\DRIVERS\Tvti2c.sys [2007-05-22 16:59]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\b57nd60x.sys [2006-11-02 09:30]
S3 btwaudio;Bluetooth-Audiogerät;C:\Windows\system32\drivers\btwaudio.sys [2007-03-29 20:46]
S3 btwavdt;Bluetooth AVDT;C:\Windows\system32\drivers\btwavdt.sys [2007-02-27 07:20]
S3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys [2007-02-27 07:20]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);"c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
*Newly Created Service* - COMHOST
.
Inhalt des "geplante Tasks" Ordners
"2008-04-28 21:06:00 C:\Windows\Tasks\Auf Updates für Windows Live Toolbar prüfen.job"
- c:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-04-27 09:47:21 C:\Windows\Tasks\Norton Internet Security - Systemprüfung ausführen - Patrick.job"
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeB/TASK:
"2008-04-28 16:37:32 C:\Windows\Tasks\User_Feed_Synchronization-{7FB51E8E-F57E-4D8A-916A-1207E2509139}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-28 23:23:37
Windows 6.0.6000 NTFS
Scanne versteckte Prozesse...
Scanne versteckte Autostart Einträge...
Scanne versteckte Dateien...
folder error: C:\Windows\system32\drivers\
folder error: C:\Windows\system32\wbem\
folder error: C:\Windows\system32\
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
**************************************************************************
.
Zeit der Fertigstellung: 2008-04-28 23:24:17
ComboFix-quarantined-files.txt 2008-04-28 21:24:13
17 Verzeichnis(se), 61,655,859,200 Bytes frei
26 Verzeichnis(se), 61,624,766,464 Bytes frei
495 --- E O F --- 2008-04-27 19:20:44
WalkerTXRanger
2008-04-29, 18:46
Here you go :)
ComboFix 08-04-27.3 - Patrick 2008-04-28 23:22:14.2 - NTFSx86
Microsoft® Windows Vista™ Business 6.0.6000.0.1252.1.1031.18.1503 [GMT 2:00]
ausgeführt von:: C:\Users\Patrick\Desktop\ComboFix.exe
Command switches used :: C:\Users\Patrick\Desktop\CFScript.txt
* Neuer Wiederherstellungspunkt wurde erstellt
FILE ::
E:\Launch.exe
.
((((((((((((((((((((((( Dateien erstellt von 2008-03-28 bis 2008-04-28 ))))))))))))))))))))))))))))))
.
2008-04-27 18:21 . 2008-04-27 18:21 <DIR> d-------- C:\Users\All Users\TEMP
2008-04-27 18:21 . 2008-04-27 18:21 <DIR> d-------- C:\ProgramData\TEMP
2008-04-27 18:20 . 2008-04-27 18:23 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-04-27 18:20 . 2005-08-25 18:19 115,920 --a------ C:\Windows\System32\MSINET.OCX
2008-04-27 16:33 . 2008-04-27 16:33 <DIR> d-------- C:\_OTMoveIt
2008-04-27 15:46 . 2008-04-27 15:46 <DIR> d-------- C:\_SMA
2008-04-27 15:27 . 2008-04-27 15:27 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-27 13:17 . 2008-04-27 13:17 <DIR> d-------- C:\Windows\System32\Kaspersky Lab
2008-04-27 11:15 . 2008-04-27 11:29 <DIR> d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-04-27 11:15 . 2008-04-27 11:29 <DIR> d-------- C:\ProgramData\Spybot - Search & Destroy
2008-04-27 11:15 . 2008-04-27 11:15 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-27 01:13 . 2008-04-27 01:13 <DIR> d-------- C:\Program Files\TeXnicCenter
2008-04-27 01:07 . 2008-04-27 01:07 <DIR> d-------- C:\Users\Patrick\AppData\Roaming\MiKTeX
2008-04-27 00:51 . 2008-04-27 01:04 <DIR> d-------- C:\Program Files\MiKTeX 2.7
2008-04-26 15:14 . 2008-04-26 15:14 194,560 --a------ C:\Windows\System32\WebClnt.dll
2008-04-26 15:14 . 2008-04-26 15:14 110,080 --a------ C:\Windows\System32\drivers\mrxdav.sys
2008-04-26 15:13 . 2008-04-26 15:13 1,060,920 --a------ C:\Windows\System32\drivers\ntfs.sys
2008-04-26 15:06 . 2008-04-26 15:06 2,027,008 --a------ C:\Windows\System32\win32k.sys
2008-04-26 15:05 . 2008-04-26 15:05 4,247,552 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-04-26 15:05 . 2008-04-26 15:05 1,686,528 --a------ C:\Windows\System32\gameux.dll
2008-04-26 15:05 . 2008-04-26 15:05 296,448 --a------ C:\Windows\System32\gdi32.dll
2008-04-26 15:04 . 2008-04-26 15:04 558,080 --a------ C:\Windows\System32\oleaut32.dll
2008-04-26 15:03 . 2008-04-26 15:03 148,992 --a------ C:\Windows\System32\drivers\ks.sys
2008-04-26 15:03 . 2008-04-26 15:03 83,968 --a------ C:\Windows\System32\dnsrslvr.dll
2008-04-26 15:03 . 2008-04-26 15:03 24,576 --a------ C:\Windows\System32\dnscacheugc.exe
2008-04-26 14:59 . 2008-04-26 14:59 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-04-26 11:07 . 2008-04-28 20:20 27,525 --a------ C:\Users\Patrick\AppData\Roaming\nvModes.dat
2008-04-26 08:37 . 2008-04-26 08:37 1,712,984 --a------ C:\Windows\System32\wuaueng.dll
2008-04-26 08:37 . 2008-04-26 08:37 1,524,224 --a------ C:\Windows\System32\wucltux.dll
2008-04-26 08:37 . 2008-04-26 08:37 53,080 --a------ C:\Windows\System32\wuauclt.exe
2008-04-26 08:37 . 2008-04-26 08:37 43,352 --a------ C:\Windows\System32\wups2.dll
2008-04-26 08:36 . 2008-04-26 08:36 549,720 --a------ C:\Windows\System32\wuapi.dll
2008-04-26 08:36 . 2008-04-26 08:36 163,000 --a------ C:\Windows\System32\wuwebv.dll
2008-04-26 08:36 . 2008-04-26 08:36 80,896 --a------ C:\Windows\System32\wudriver.dll
2008-04-26 08:36 . 2008-04-26 08:36 33,624 --a------ C:\Windows\System32\wups.dll
2008-04-26 08:36 . 2008-04-26 08:36 31,232 --a------ C:\Windows\System32\wuapp.exe
2008-04-26 08:25 . 2008-04-26 08:25 <DIR> d-------- C:\Program Files\Common Files\Deterministic Networks
2008-04-26 08:25 . 2007-01-31 13:45 127,376 --a------ C:\Windows\System32\drivers\dne2000.sys
2008-04-26 08:25 . 2007-01-31 13:45 101,904 --a------ C:\Windows\System32\dneinobj.dll
2008-04-26 08:24 . 2008-04-26 08:24 <DIR> d-------- C:\Program Files\Cisco Systems
2008-04-26 08:24 . 2008-04-26 08:26 1,593 --a------ C:\Windows\VPNInstall.MIF
2008-04-25 17:08 . 2008-04-25 17:27 <DIR> d-------- C:\Installs
2008-04-25 16:40 . 2008-04-25 16:47 <DIR> d-------- C:\Lebenslauf
2008-04-25 16:33 . 2008-04-25 16:33 <DIR> d-------- C:\Users\Patrick\AppData\Roaming\GMX
2008-04-25 16:33 . 2008-04-25 16:33 <DIR> d-------- C:\Users\All Users\GMX
2008-04-25 16:33 . 2008-04-25 16:33 <DIR> d-------- C:\ProgramData\GMX
2008-04-25 16:33 . 2008-04-25 16:33 <DIR> d-------- C:\Program Files\GMX
2008-04-25 16:33 . 2008-04-01 12:54 90,112 --a------ C:\Windows\System32\UIGMXMON.DLL
2008-04-25 11:02 . 2008-04-25 11:02 <DIR> d-------- C:\Users\Patrick\AppData\Roaming\Leadertech
2008-04-25 10:59 . 2008-04-26 10:26 <DIR> d-------- C:\Users\Patrick\.freemind
2008-04-25 10:40 . 2008-04-25 10:40 <DIR> d-------- C:\Users\Patrick\AppData\Roaming\Talkback
2008-04-25 09:58 . 2008-04-25 09:59 <DIR> d-------- C:\Users\Patrick\AppData\Roaming\Thunderbird
2008-04-25 09:58 . 2008-04-25 09:58 <DIR> d-------- C:\Program Files\Mozilla Thunderbird
2008-04-25 09:47 . 2008-04-25 11:02 <DIR> d-------- C:\Program Files\FreeMind
2008-04-25 01:14 . 2008-04-28 17:47 <DIR> dr------- C:\MPICC
2008-04-25 01:06 . 2008-02-03 09:20 47,680 --a------ C:\Windows\System32\drivers\tvtumon.sys
2008-04-25 00:41 . 2008-04-25 00:43 <DIR> d-------- C:\Users\Patrick\AppData\Roaming\Winamp
2008-04-25 00:41 . 2008-04-25 00:42 <DIR> d-------- C:\Program Files\Winamp
2008-04-25 00:13 . 2008-04-28 20:25 <DIR> d-------- C:\Users\Patrick\AppData\Roaming\skypePM
2008-04-25 00:13 . 2008-04-25 00:13 32 --a------ C:\Users\All Users\ezsid.dat
2008-04-25 00:13 . 2008-04-25 00:13 32 --a------ C:\ProgramData\ezsid.dat
2008-04-25 00:11 . 2008-04-28 23:23 <DIR> d-------- C:\Users\Patrick\AppData\Roaming\Skype
2008-04-25 00:10 . 2008-04-25 00:10 <DIR> d-------- C:\Users\All Users\Skype
2008-04-25 00:10 . 2008-04-25 00:10 <DIR> d-------- C:\ProgramData\Skype
2008-04-25 00:10 . 2008-04-25 00:10 <DIR> d-------- C:\Program Files\Skype
2008-04-25 00:10 . 2008-04-25 00:10 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-04-25 00:07 . 2008-04-28 20:20 <DIR> d-------- C:\Users\Patrick\AppData\Roaming\OpenOffice.org2
2008-04-24 23:56 . 2008-04-25 00:16 <DIR> d-------- C:\Program Files\Mozilla Firefox 3 Beta 5
2008-04-24 23:53 . 2008-04-28 20:19 2,080 --a------ C:\Windows\System32\ICAutoUpdate.log.bak
2008-04-24 23:46 . 2008-04-26 08:30 213,757,563 --a------ C:\sysiclog.txt.bak
2008-04-24 20:11 . 2008-04-24 20:11 <DIR> d-------- C:\Program Files\Common Files\ThinkVantage Fingerprint Software
2008-04-24 20:07 . 2008-04-24 20:07 33,536 --a------ C:\Windows\System32\drivers\tvtfilter.sys
2008-04-24 19:51 . 2008-04-24 19:51 390,144 --a------ C:\Windows\System32\wlangpui.dll
2008-04-24 19:51 . 2008-04-24 19:51 225,792 --a------ C:\Windows\System32\dot3gpui.dll
2008-04-24 19:51 . 2008-04-24 19:51 223,526 --a------ C:\Windows\System32\onex.tmf
2008-04-24 19:51 . 2008-04-24 19:51 162,816 --a------ C:\Windows\System32\onex.dll
2008-04-24 19:51 . 2008-04-24 19:51 146,944 --a------ C:\Windows\System32\dot3svc.dll
2008-04-24 19:51 . 2008-04-24 19:51 141,824 --a------ C:\Windows\System32\dot3ui.dll
2008-04-24 19:51 . 2008-04-24 19:51 72,192 --a------ C:\Windows\System32\dot3msm.dll
2008-04-24 19:51 . 2008-04-24 19:51 45,568 --a------ C:\Windows\System32\dot3dlg.dll
2008-04-24 19:51 . 2008-04-24 19:51 26,112 --a------ C:\Windows\System32\dot3api.dll
2008-04-24 19:50 . 2008-04-24 19:51 199,680 --a------ C:\Windows\System32\wlanui.dll
2008-04-24 19:48 . 2008-04-24 19:48 54,784 --a------ C:\Windows\System32\drivers\i8042prt.sys
2008-04-24 19:48 . 2008-04-24 19:48 35,512 --a------ C:\Windows\System32\drivers\kbdclass.sys
2008-04-24 19:46 . 2008-04-24 19:46 <DIR> d-------- C:\Users\All Users\Intel
2008-04-24 19:46 . 2008-04-24 19:46 <DIR> d-------- C:\ProgramData\Intel
2008-04-24 19:46 . 2008-04-24 19:46 <DIR> d-------- C:\Program Files\Cisco
2008-04-24 19:41 . 2008-04-24 19:41 188 --a------ C:\Windows\x
2008-04-24 18:34 . 2008-04-28 10:32 <DIR> d-------- C:\Uni
2008-04-24 18:21 . 2008-04-25 11:36 <DIR> d-------- C:\MP3s
2008-04-24 17:55 . 2008-04-24 17:55 47 --a------ C:\Windows\System32\drivers\IBM_7663_PJG.MRK
2008-04-24 17:38 . 2008-04-24 17:38 <DIR> d-------- C:\Program Files\OpenOffice.org 2.4
2008-04-24 17:29 . 2008-04-24 17:29 <DIR> d-------- C:\Users\All Users\Mindjet
2008-04-24 17:29 . 2008-04-24 17:29 <DIR> d-------- C:\ProgramData\Mindjet
2008-04-24 17:29 . 2008-04-24 17:29 <DIR> d-------- C:\Program Files\Mindjet
2008-04-24 17:29 . 2004-12-07 07:11 258,352 --a------ C:\Windows\System32\unicows.dll
2008-04-24 17:29 . 2006-01-30 09:32 5,632 --a------ C:\Windows\System32\pxc25pm.dll
2008-04-24 17:28 . 2008-04-24 17:28 16 --a------ C:\Windows\System32\coh.cache
2008-04-24 17:18 . 2008-04-24 17:18 0 --a------ C:\Windows\nsreg.dat
2008-04-24 17:04 . 2008-04-24 23:48 <DIR> d-------- C:\Users\Patrick\AppData\Roaming\Lenovo
2008-04-24 17:00 . 2006-11-02 15:04 <DIR> dr------- C:\Users\Patrick\Videos
2008-04-24 17:00 . 2008-04-24 17:02 <DIR> dr------- C:\Users\Patrick\Searches
2008-04-24 17:00 . 2006-11-02 15:04 <DIR> dr------- C:\Users\Patrick\Saved Games
2008-04-24 17:00 . 2006-11-02 15:04 <DIR> dr------- C:\Users\Patrick\Pictures
2008-04-24 17:00 . 2006-11-02 15:04 <DIR> dr------- C:\Users\Patrick\Music
2008-04-24 17:00 . 2008-04-24 17:02 <DIR> dr------- C:\Users\Patrick\Links
2008-04-24 17:00 . 2008-04-27 20:41 <DIR> dr------- C:\Users\Patrick\Downloads
2008-04-24 17:00 . 2008-04-25 00:02 <DIR> dr------- C:\Users\Patrick\Documents
2008-04-24 17:00 . 2006-11-02 15:04 <DIR> dr------- C:\Users\Patrick\Contacts
2008-04-24 17:00 . 2006-11-02 15:04 <DIR> d--h----- C:\Users\Patrick\AppData
2008-04-24 17:00 . 2008-04-26 08:25 <DIR> d-------- C:\Users\Patrick
2008-04-24 17:00 . 2008-04-24 17:00 <DIR> d-------- C:\Program Files\Windows Live Toolbar
2008-04-24 17:00 . 2008-04-24 17:08 524,288 --ahs---- C:\Users\Patrick\NTUSER.DAT{3d4e88f1-6a70-11db-b1ba-d64300c9c793}.TMContainer00000000000000000002.regtrans-ms
2008-04-24 17:00 . 2008-04-24 17:08 524,288 --ahs---- C:\Users\Patrick\NTUSER.DAT{3d4e88f1-6a70-11db-b1ba-d64300c9c793}.TMContainer00000000000000000001.regtrans-ms
2008-04-24 17:00 . 2008-04-28 23:23 262,144 --ah----- C:\Users\Patrick\ntuser.dat.LOG1
2008-04-24 17:00 . 2008-04-24 17:08 65,536 --ahs---- C:\Users\Patrick\NTUSER.DAT{3d4e88f1-6a70-11db-b1ba-d64300c9c793}.TM.blf
2008-04-24 17:00 . 2008-04-24 17:00 10 --a------ C:\Windows\System32\firstboot.lgl
2008-04-24 17:00 . 2008-04-24 17:00 0 --ah----- C:\Users\Patrick\ntuser.dat.LOG2
2008-04-24 16:55 . 2008-04-24 16:55 <DIR> dr------- C:\Windows\System32\config\systemprofile\Contacts
7 Datei(en), . 3,473,428 C:\ComboFix\Bytes
4 Datei(en), . 128,250 C:\ComboFix\Bytes
4 Datei(en), . 128,250 C:\ComboFix\Bytes
2 Datei(en), . 55,050 C:\ComboFix\Bytes
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-27 13:23 1,732 ----a-w C:\tvtpktfilter.dat
2008-04-26 13:20 --------- d-----w C:\Program Files\Windows Mail
2008-04-26 13:15 --------- d-----w C:\ProgramData\Microsoft Help
2008-04-26 13:10 --------- d-----w C:\Program Files\Microsoft SQL Server
2008-04-26 13:07 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys
2008-04-26 13:07 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys
2008-04-26 13:07 3,505,720 ----a-w C:\Windows\System32\ntkrnlpa.exe
2008-04-26 13:07 3,471,928 ----a-w C:\Windows\System32\ntoskrnl.exe
2008-04-26 13:07 24,064 ----a-w C:\Windows\System32\netcfg.exe
2008-04-26 13:07 22,016 ----a-w C:\Windows\System32\netiougc.exe
2008-04-26 13:07 216,632 ----a-w C:\Windows\system32\drivers\netio.sys
2008-04-26 13:07 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys
2008-04-26 13:07 17,464 ----a-w C:\Windows\system32\drivers\intelide.sys
2008-04-26 13:07 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
2008-04-26 13:07 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys
2008-04-26 13:07 109,624 ----a-w C:\Windows\system32\drivers\ataport.sys
2008-04-26 13:05 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-04-26 13:05 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-04-26 13:05 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
2008-04-26 13:05 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-04-26 13:05 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-04-26 13:01 826,368 ----a-w C:\Windows\System32\wininet.dll
2008-04-26 13:01 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-04-26 13:01 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-04-26 13:01 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-04-26 06:54 --------- d-----w C:\Program Files\ThinkVantage
2008-04-26 06:45 --------- d-----w C:\ProgramData\Symantec
2008-04-24 23:06 --------- d-----w C:\Program Files\Common Files\Lenovo
2008-04-24 22:05 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-24 18:24 --------- d-----w C:\Program Files\ThinkVantage Fingerprint Software
2008-04-24 18:13 --------- d-----w C:\Program Files\InterVideo
2008-04-24 18:11 --------- d-----w C:\ProgramData\UIB
2008-04-24 18:07 --------- d-----w C:\Program Files\Lenovo
2008-04-24 17:57 129,784 ------w C:\Windows\System32\PxAFS.DLL
2008-04-24 17:55 --------- d-----w C:\Program Files\Analog Devices
2008-04-24 17:52 --------- d-----w C:\ProgramData\Lenovo
2008-04-24 17:49 --------- d-----w C:\Program Files\PCDR5
2008-04-24 17:45 --------- d-----w C:\Program Files\Intel
2008-04-24 17:38 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-24 15:38 --------- d-----w C:\Program Files\Java
2008-04-24 15:31 --------- d-----w C:\Program Files\Norton Internet Security
2008-04-24 15:24 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-24 15:23 805 ----a-w C:\Windows\system32\drivers\SYMEVENT.INF
2008-04-24 15:23 123,952 ----a-w C:\Windows\system32\drivers\SYMEVENT.SYS
2008-04-24 15:23 10,740 ----a-w C:\Windows\system32\drivers\SYMEVENT.CAT
2008-04-24 15:23 --------- d-----w C:\Program Files\Symantec
2008-04-24 15:00 100 ----a-w C:\Windows\system32\drivers\Lenovo_7663_PJG.MRK
2008-04-24 14:56 --------- d-sh--w C:\ProgramData\Vorlagen
2008-04-24 14:56 --------- d-sh--w C:\ProgramData\Startmenü
2008-04-24 14:56 --------- d-sh--w C:\ProgramData\Favoriten
2008-04-24 14:56 --------- d-sh--w C:\ProgramData\Dokumente
2008-04-24 14:56 --------- d-sh--w C:\ProgramData\Anwendungsdaten
2008-04-24 14:56 --------- d-sh--w C:\Program Files\Gemeinsame Dateien
2008-03-23 15:15 974,336 ----a-w C:\Windows\System32\crypt32.dll
2008-03-23 15:14 29,184 ----a-w C:\Windows\system32\drivers\BTHUSB.SYS
2008-03-23 15:14 25,656 ----a-w C:\Windows\system32\drivers\msahci.sys
2008-03-23 15:14 220,160 ----a-w C:\Windows\system32\drivers\bthport.sys
2008-03-23 15:14 211,000 ----a-w C:\Windows\system32\drivers\volsnap.sys
2008-03-23 15:14 20,024 ------w C:\Windows\system32\drivers\viaide.sys
2008-03-23 15:14 19,456 ----a-w C:\Windows\system32\drivers\bthenum.sys
2008-03-23 15:14 19,000 ------w C:\Windows\system32\drivers\cmdide.sys
2008-03-23 15:14 181,760 ----a-w C:\Windows\System32\fsquirt.exe
2008-03-23 15:14 17,976 ------w C:\Windows\system32\drivers\amdide.sys
2008-03-23 15:14 17,464 ------w C:\Windows\system32\drivers\aliide.sys
2008-03-23 15:14 15,928 ------w C:\Windows\system32\drivers\pciide.sys
2008-03-23 15:14 --------- d-----w C:\Program Files\Windows Sidebar
2008-03-23 15:13 11,776 ----a-w C:\Windows\System32\sbunattend.exe
2008-03-23 15:12 84,992 ----a-w C:\Windows\system32\drivers\srvnet.sys
2008-03-23 15:12 58,368 ----a-w C:\Windows\system32\drivers\mrxsmb20.sys
2008-03-23 15:12 2,048 ----a-w C:\Windows\System32\tzres.dll
2008-03-23 15:12 130,048 ----a-w C:\Windows\system32\drivers\srv2.sys
2008-03-23 15:12 101,888 ----a-w C:\Windows\system32\drivers\mrxsmb.sys
2008-03-23 15:09 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
2008-03-23 15:08 750,080 ----a-w C:\Windows\System32\qmgr.dll
2008-03-23 15:06 53,760 ----a-w C:\Windows\system32\drivers\hdaudbus.sys
2008-03-23 15:06 13,312 ------w C:\Windows\system32\drivers\sffdisk.sys
2008-03-23 15:06 12,800 ------w C:\Windows\system32\drivers\sffp_sd.sys
2008-03-23 15:06 12,800 ------w C:\Windows\system32\drivers\sffp_mmc.sys
2008-03-23 15:05 86,016 ----a-w C:\Windows\System32\icfupgd.dll
2008-03-23 15:05 63,488 ----a-w C:\Windows\system32\drivers\mpsdrv.sys
2008-03-23 15:05 61,952 ----a-w C:\Windows\System32\cmifw.dll
2008-03-23 15:05 396,800 ----a-w C:\Windows\System32\MPSSVC.dll
2008-03-23 15:05 392,192 ----a-w C:\Windows\System32\FirewallAPI.dll
2008-03-23 15:05 374,456 ----a-w C:\Windows\System32\mcupdate_GenuineIntel.dll
2008-03-23 15:05 23,040 ----a-w C:\Windows\system32\drivers\tunnel.sys
2008-03-23 15:05 2,048 ----a-w C:\Windows\System32\msxml3r.dll
2008-03-23 15:05 178,688 ----a-w C:\Windows\System32\iphlpsvc.dll
2008-03-23 15:05 16,896 ----a-w C:\Windows\System32\wfapigp.dll
2008-03-23 15:05 15,360 ----a-w C:\Windows\system32\drivers\TUNMP.SYS
2008-03-23 15:05 1,191,936 ----a-w C:\Windows\System32\msxml3.dll
2008-03-23 15:03 5,120 ----a-w C:\Windows\System32\wmi.dll
2008-03-23 15:03 152,576 ----a-w C:\Windows\System32\imagehlp.dll
2008-03-23 15:03 12,800 ----a-w C:\Windows\system32\drivers\fs_rec.sys
2008-03-23 15:03 104,448 ----a-w C:\Windows\System32\DWWIN.EXE
2008-03-23 15:03 --------- d-----w C:\Program Files\Windows Defender
2008-03-23 15:02 74,752 ----a-w C:\Windows\system32\drivers\rasl2tp.sys
2008-03-23 15:02 60,928 ----a-w C:\Windows\system32\drivers\raspptp.sys
2008-03-23 15:02 500,224 ----a-w C:\Windows\System32\msdtcprx.dll
2008-03-23 15:02 49,664 ----a-w C:\Windows\System32\csrsrv.dll
2008-03-23 15:02 376,320 ----a-w C:\Windows\System32\winsrv.dll
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\Windows\x ----
C:\Windows\x\
((((((((((((((((((((((((((((( snapshot@2008-04-27_17.04.17.25 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-26 13:00:48 1,257,472 ----a-w C:\Windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
+ 2008-04-27 15:34:59 1,265,664 ----a-w C:\Windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
- 2008-04-26 13:00:49 1,224,704 ----a-w C:\Windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
+ 2008-04-27 15:34:59 1,232,896 ----a-w C:\Windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
+ 2008-04-27 15:35:08 61,440 ----a-w C:\Windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_990d8bcd\CustomMarshalers.dll
+ 2008-04-27 15:35:32 118,784 ----a-w C:\Windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_b61164fe\CustomMarshalers.dll
+ 2008-04-27 16:05:03 8,908,800 ----a-w C:\Windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_2f8cf300\mscorlib.dll
+ 2008-04-27 15:35:25 3,391,488 ----a-w C:\Windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_f6a1eb32\mscorlib.dll
+ 2008-04-27 15:35:22 1,470,464 ----a-w C:\Windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_6285ba7c\System.Design.dll
+ 2008-04-27 16:04:56 3,395,584 ----a-w C:\Windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_c4fb35a2\System.Design.dll
+ 2008-04-27 15:35:09 90,112 ----a-w C:\Windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_7afa4606\System.Drawing.Design.dll
+ 2008-04-27 16:04:39 192,512 ----a-w C:\Windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_bcef0bec\System.Drawing.Design.dll
+ 2008-04-27 15:35:23 835,584 ----a-w C:\Windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_27b26e49\System.Drawing.dll
+ 2008-04-27 16:04:59 2,244,608 ----a-w C:\Windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_34771d7f\System.Drawing.dll
+ 2008-04-27 16:04:48 7,884,800 ----a-w C:\Windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_837c0fe0\System.Windows.Forms.dll
+ 2008-04-27 15:35:14 3,018,752 ----a-w C:\Windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_a55d4a65\System.Windows.Forms.dll
+ 2008-04-27 16:04:52 5,513,216 ----a-w C:\Windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_1fd1a873\System.Xml.dll
+ 2008-04-27 15:35:18 2,088,960 ----a-w C:\Windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_5837028e\System.Xml.dll
+ 2008-04-27 15:35:31 4,788,224 ----a-w C:\Windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_4ee31964\System.dll
+ 2008-04-27 15:35:07 1,966,080 ----a-w C:\Windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_b9993d57\System.dll
- 2008-04-27 15:00:49 67,584 --s-a-w C:\Windows\bootstat.dat
+ 2008-04-28 18:19:05 67,584 --s-a-w C:\Windows\bootstat.dat
+ 2008-04-27 15:35:13 32,768 ----a-r C:\Windows\Installer\{C523D256-313D-4866-B36A-F3DE528246EF}\icon.exe
- 2004-07-14 23:49:16 258,048 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2007-04-13 19:30:52 258,048 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
- 2004-07-14 23:49:22 32,768 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
+ 2007-04-13 19:30:52 32,768 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
- 2004-07-14 22:32:22 81,920 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
+ 2007-04-13 18:57:52 81,920 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
- 2003-02-20 18:09:14 86,016 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
+ 2007-04-13 18:57:58 86,016 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
- 2004-07-14 22:25:06 315,392 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
+ 2007-04-13 18:56:30 315,392 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
- 2004-07-14 22:33:04 102,400 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
+ 2007-04-13 18:58:00 102,400 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
- 2004-07-15 12:29:02 2,138,112 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2007-04-13 18:50:46 2,142,208 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
- 2003-02-20 18:09:18 77,824 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
+ 2007-04-13 18:58:02 77,824 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
- 2004-07-14 22:26:52 2,510,848 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
+ 2007-04-13 18:57:00 2,523,136 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
- 2004-07-14 22:28:34 2,502,656 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2007-04-13 18:57:28 2,514,944 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
- 2004-08-10 14:20:00 106,496 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe
+ 2007-01-15 14:11:26 73,728 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe
+ 2004-07-14 23:49:16 258,048 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\SHADOW4308\_aspnet_isapi.dll
+ 2004-07-14 22:32:22 81,920 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\SHADOW4308\_CORPerfMonExt.dll
+ 2004-07-14 22:24:30 282,624 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\SHADOW4308\_fusion.dll
+ 2004-07-14 22:25:06 315,392 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\SHADOW4308\_mscorjit.dll
+ 2004-07-15 12:29:02 2,138,112 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\SHADOW4308\_mscorlib.dll
+ 2003-02-20 18:09:18 77,824 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\SHADOW4308\_mscorsn.dll
+ 2004-07-14 22:26:52 2,510,848 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\SHADOW4308\_mscorsvr.dll
+ 2004-07-14 22:28:34 2,502,656 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\SHADOW4308\_mscorwks.dll
+ 2003-02-21 03:42:22 348,160 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\SHADOW4308\_msvcr71.dll
+ 2004-07-14 22:34:50 94,208 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\SHADOW4308\_PerfCounter.dll
- 2004-07-15 12:31:16 1,224,704 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\System.dll
+ 2007-04-13 19:35:38 1,232,896 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\System.dll
- 2004-07-15 12:29:00 1,257,472 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
+ 2007-04-13 19:35:46 1,265,664 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
+ 2008-04-28 18:19:06 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-04-28 18:19:06 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2008-04-27 15:01:57 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-04-28 18:21:21 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
- 2008-04-27 15:01:57 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-04-28 18:21:13 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-04-28 18:21:13 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2008-04-27 13:46:38 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-04-28 13:57:24 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-04-27 13:46:38 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-04-28 13:57:24 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-04-27 13:46:38 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-04-28 13:57:24 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-04-27 14:57:12 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
+ 2008-04-28 21:22:08 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
+ 2008-04-28 21:22:08 262,144 ---ha-w C:\Windows\System32\config\systemprofile\ntuser.dat.LOG1
- 2007-05-08 13:03:04 1,275,392 ----a-w C:\Windows\System32\msxml4.dll
+ 2007-08-24 16:08:24 1,275,392 ----a-w C:\Windows\System32\msxml4.dll
+ 2008-04-28 13:04:43 2,456 ----a-w C:\Windows\System32\networklist\icons\{FC3C5758-222D-4F1D-92BC-023FB7B47029}_24.bin
+ 2008-04-28 13:04:43 4,280 ----a-w C:\Windows\System32\networklist\icons\{FC3C5758-222D-4F1D-92BC-023FB7B47029}_32.bin
+ 2008-04-28 13:04:43 9,560 ----a-w C:\Windows\System32\networklist\icons\{FC3C5758-222D-4F1D-92BC-023FB7B47029}_48.bin
- 2008-04-27 09:46:48 6,291,456 ----a-w C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2008-04-27 19:21:07 6,291,456 ----a-w C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT
- 2008-04-27 14:38:53 3,740 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1748752477-3087473287-3414825192-1005_UserData.bin
+ 2008-04-28 18:21:41 4,184 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1748752477-3087473287-3414825192-1005_UserData.bin
- 2008-04-27 14:38:53 73,946 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-04-28 18:21:40 74,510 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-04-27 14:38:48 45,764 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-04-28 18:21:37 48,448 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-04-27 19:20:23 1,744,384 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\apds.dll
+ 2008-04-27 19:20:25 222,208 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\apircl.dll
+ 2008-04-27 19:20:23 199,168 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\apss.dll
+ 2008-04-27 19:20:24 534,528 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\CbsCore.dll
+ 2008-04-27 19:20:24 22,016 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\CbsMsg.dll
+ 2008-04-27 19:20:24 119,808 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\cmiadapter.dll
+ 2008-04-27 19:20:25 271,360 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\cmitrust.dll
+ 2008-04-27 19:20:26 2,032,640 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\cmiv2.dll
+ 2008-04-27 19:20:25 238,592 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\CntrtextInstaller.dll
+ 2008-04-27 19:20:23 258,560 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\dpx.dll
+ 2008-04-27 19:20:26 99,840 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\DrUpdate.dll
+ 2008-04-27 19:20:25 246,784 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\drvstore.dll
+ 2008-04-27 19:20:24 263,168 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\esscli.dll
+ 2008-04-27 19:20:24 614,400 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\fastprox.dll
+ 2008-04-27 19:20:24 100,352 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\helpcins.dll
+ 2008-04-27 19:20:25 222,720 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\locdrv.dll
+ 2008-04-27 19:20:27 191,488 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\mofd.dll
+ 2008-04-27 19:20:25 102,400 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\mofinstall.dll
+ 2008-04-27 19:20:24 305,152 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\msdelta.dll
+ 2008-04-27 19:20:24 35,328 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\mspatcha.dll
+ 2008-04-27 19:20:25 146,432 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\OEMHelpIns.dll
+ 2008-04-27 19:20:25 130,560 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\PkgMgr.exe
+ 2008-04-27 19:20:24 118,272 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\poqexec.exe
+ 2008-04-27 19:20:27 264,704 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\repdrvfs.dll
+ 2008-04-27 19:20:23 126,464 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\rescinst.dll
+ 2008-04-27 19:20:25 704,512 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\smiengine.dll
+ 2008-04-27 19:20:24 139,264 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\SmiInstaller.dll
+ 2008-04-27 19:20:25 116,736 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\smipi.dll
+ 2008-04-27 19:20:27 357,888 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\wbemcomn.dll
+ 2008-04-27 19:20:27 742,912 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\wbemcore.dll
+ 2008-04-27 19:20:26 30,208 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\wbemprox.dll
+ 2008-04-27 19:20:26 1,832,448 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\wcp.dll
+ 2008-04-27 19:20:25 218,624 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\wdscore.dll
+ 2008-04-27 19:20:24 83,968 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\wmiutils.dll
+ 2008-04-27 19:20:26 51,712 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\wrpint.dll
+ 2008-04-27 19:20:26 183,296 ----a-w C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\xmllite.dll
+ 2008-04-27 15:35:13 1,275,392 ----a-w C:\Windows\winsxs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9849.0_none_b7e911727b2899b7\msxml4.dll
.
-- Snapshot reset to current date --
.
(((((((((((((((((((((((((((( Autostart Punkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Hinweis* leere Eintrage & legitime Standardeintrage werden nicht angezeigt.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BF468356-BB7E-42D7-9F15-4F3B9BCFCED2}]
2008-02-19 13:05 784960 --a------ C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-03-23 17:13 1232896]
"WindowsWelcomeCenter"="oobefldr.dll" [2006-11-02 14:35 2159104 C:\Windows\System32\oobefldr.dll]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-03-23 17:03 1006264]
"TPFNF7"="C:\PROGRA~1\Lenovo\NPDIRECT\TPFNF7SP.exe" [2008-03-26 03:06 59680]
"PWMTRV"="C:\PROGRA~1\ThinkPad\UTILIT~1\PWMTR32V.DLL" [2008-01-11 02:20 558368]
"BLOG"="C:\PROGRA~1\ThinkPad\UTILIT~1\BTVLogEx.DLL" [2008-01-11 02:20 214576]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-11-21 18:08 820520]
"TPHOTKEY"="C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe" [2008-01-24 10:21 66928]
"TpShocks"="TpShocks.exe" [2007-11-22 16:09 181536 C:\Windows\System32\TpShocks.exe]
"EZEJMNAP"="C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2007-04-27 02:33 243248]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-07-27 09:57 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-07-27 09:57 8433664]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-07-27 09:57 81920]
"LenovoOobeOffers"="c:\SWTOOLS\LenovoWelcome\LenovoOobeOffers.exe" [2007-09-25 21:53 28672]
"TVT Scheduler Proxy"="C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2008-03-04 10:34 487424]
"DiskeeperSystray"="C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-11-15 17:21 217176]
"AwaySch"="C:\Program Files\Lenovo\AwayTask\AwaySch.EXE" [2006-11-07 12:51 91688]
"LPManager"="C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe" [2008-01-11 02:21 144728]
"AMSG"="C:\Program Files\ThinkVantage\AMSG\Amsg.exe" [2007-02-01 20:00 419376]
"RoxioDragToDisc"="C:\Program Files\Lenovo\Drag-to-Disc\DrgToDsc.exe" [2007-03-13 10:05 1116920]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42 144784]
"ACTray"="C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe" [2008-03-17 13:37 431392]
"ACWLIcon"="C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2008-03-17 13:37 128288]
"IaNvSrv"="C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe" [2007-10-24 03:02 33304]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 23:59 115816]
"MMReminderService"="C:\Program Files\Mindjet\MindManager 7\MMReminderService.exe" [2007-05-18 00:05 37392]
"LPMailChecker"="C:\PROGRA~1\THINKV~2\PrdCtr\LPMLCHK.exe" [2008-01-11 02:21 124248]
"cssauth"="C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" [2007-11-29 18:36 2872632]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2007-12-07 10:13 1282048]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"WinampAgent"="C:\Programme\Winamp\winampa.exe" [2008-04-01 20:49 36352]
C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 15:41:28 393216]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
BTTray.lnk - C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe [2007-03-29 14:11:50 719664]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2008-03-23 08:41:16 50688]
LenovoRegistration.lnk - C:\SWTOOLS\LenovoWelcome\LenovoRegistration.cmd [2007-10-04 21:41:21 166]
VPN Client.lnk - C:\Windows\Installer\{CCBAA1F7-E5E1-48B2-9ED9-A79C6A37CE78}\Icon3E5562ED7.ico [2008-04-26 08:26:34 6144]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
C:\Windows\system32\psqlpwd.dll 2007-08-14 15:54 89600 C:\Windows\System32\psqlpwd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{8A39DB58-28DD-4BA3-970A-BC1E6A43FFFE}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"TCP Query User{5BFBFD37-78F0-4B7A-BD03-DB0061B67C86}C:\\program files\\skype\\phone\\skype.exe"= UDP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"UDP Query User{05E6AF01-D3A5-4623-AF6D-9FB91D1AFC7B}C:\\program files\\skype\\phone\\skype.exe"= TCP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
R0 iaNvStor;Intel(R) Turbo Memory Controller;C:\Windows\system32\DRIVERS\iaNvStor.sys [2007-10-02 12:53]
R0 Shockprf;Shockprf;C:\Windows\system32\DRIVERS\Apsx86.sys [2007-10-16 19:33]
R0 TPDIGIMN;TPDIGIMN;C:\Windows\system32\DRIVERS\ApsHM86.sys [2007-10-16 19:32]
R1 DLARTL_M;DLARTL_M;C:\Windows\system32\Drivers\DLARTL_M.SYS [2007-02-08 21:05]
R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20080423.002\IDSvix86.sys [2008-04-04 17:47]
R1 lenovo.smi;Lenovo System Interface Driver;C:\Windows\system32\DRIVERS\smiif32.sys [2006-08-30 12:04]
R1 TPPWRIF;TPPWRIF;C:\Windows\system32\drivers\Tppwr32v.sys [2008-01-11 02:20]
R1 tvtumon;tvtumon;C:\Windows\system32\DRIVERS\tvtumon.sys [2008-02-03 09:20]
R2 AEADIFilters;Andrea ADI Filters Service;C:\Windows\system32\AEADISRV.EXE [2007-02-06 00:44]
R2 BcmSqlStartupSvc;SQL Server-Startdienst für Business Contact Manager;"C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe" [2008-01-16 09:51]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
R2 smihlp2;SMI Helper Driver (smihlp2);C:\Program Files\Common Files\ThinkVantage Fingerprint Software\Drivers\smihlp.sys [2007-08-14 15:46]
R2 SQLWriter;SQL Server VSS Writer;"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 05:29]
R2 TPHKSVC;Anzeige am Bildschirm;C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe [2007-12-14 16:37]
R2 TVT Backup Protection Service;TVT Backup Protection Service;"C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe" [2007-12-05 17:32]
R2 TVT_UpdateMonitor;TVT Windows Update Monitor;C:\Program Files\Lenovo\Rescue and Recovery\UpdateMonitor.exe [2008-02-03 09:20]
R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2006-11-28 09:44]
R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2007-01-09 16:32]
R3 TcUsb;TC USB Kernel Driver;C:\Windows\system32\Drivers\tcusb.sys [2007-08-14 15:25]
R3 TVTI2C;Lenovo SM bus driver;C:\Windows\system32\DRIVERS\Tvti2c.sys [2007-05-22 16:59]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\b57nd60x.sys [2006-11-02 09:30]
S3 btwaudio;Bluetooth-Audiogerät;C:\Windows\system32\drivers\btwaudio.sys [2007-03-29 20:46]
S3 btwavdt;Bluetooth AVDT;C:\Windows\system32\drivers\btwavdt.sys [2007-02-27 07:20]
S3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys [2007-02-27 07:20]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);"c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
*Newly Created Service* - COMHOST
.
Inhalt des "geplante Tasks" Ordners
"2008-04-28 21:06:00 C:\Windows\Tasks\Auf Updates für Windows Live Toolbar prüfen.job"
- c:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-04-27 09:47:21 C:\Windows\Tasks\Norton Internet Security - Systemprüfung ausführen - Patrick.job"
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeB/TASK:
"2008-04-28 16:37:32 C:\Windows\Tasks\User_Feed_Synchronization-{7FB51E8E-F57E-4D8A-916A-1207E2509139}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-28 23:23:37
Windows 6.0.6000 NTFS
Scanne versteckte Prozesse...
Scanne versteckte Autostart Einträge...
Scanne versteckte Dateien...
folder error: C:\Windows\system32\drivers\
folder error: C:\Windows\system32\wbem\
folder error: C:\Windows\system32\
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
**************************************************************************
.
Zeit der Fertigstellung: 2008-04-28 23:24:17
ComboFix-quarantined-files.txt 2008-04-28 21:24:13
17 Verzeichnis(se), 61,655,859,200 Bytes frei
26 Verzeichnis(se), 61,624,766,464 Bytes frei
495 --- E O F --- 2008-04-27 19:20:44
Rorschach112
2008-04-29, 20:15
Your logs are clean ! We need to do a few things
Follow these steps to uninstall Combofix and tools used in the removal of malware
Click START then RUN
Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
http://i189.photobucket.com/albums/z176/EPL47/CF_Cleanup.png
You now need to update your Java and remove your older versions.
Please follow these steps to remove older version Java components.
* Click Start > Control Panel.
* Click Add/Remove Programs.
* Check any item with Java Runtime Environment (JRE) in the name.
* Click the Remove or Change/Remove button.
Download the latest version of Java Runtime Environment (JRE), and install it to your computer from
here (http://java.sun.com/javase/downloads/index.jsp)
Make sure you have an Internet Connection.
Double-click OTMoveIt2.exe to run it.
Click on the CleanUp! button
A list of tool components used in the Cleanup of malware will be downloaded.
If your Firewall or Real Time protection attempts to block OtMoveit2 to rech the Internet, please allow the application to do so.
Click Yes to beging the Cleanup process and remove these components, including this application.
You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.
Below I have included a number of recommendations for how to protect your computer against malware infections.
* Keep Windows updated by regularly checking their website at :
http://windowsupdate.microsoft.com/
This will ensure your computer has always the latest security updates available installed on your computer.
* To reduce re-infection for malware in the future, I strongly recommend installing these free programs:
SpywareBlaster (http://www.javacoolsoftware.com/sbdownload.html) protects against bad ActiveX
IE-SPYAD (http://www.spywarewarrior.com/uiuc/res/ie-spyad.exe) puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all
Have a look at this tutorial for IE-Spyad here (http://www.bleepingcomputer.com/tutorials/tutorial53.html)
* SpywareGuard (http://www.javacoolsoftware.com/sgdownload.html) offers realtime protection from spyware installation attempts.
Make Internet Explorer more secure
Click Start > Run
Type Inetcpl.cpl & click OK
Click on the Security tab
Click Reset all zones to default level
Make sure the Internet Zone is selected & Click Custom level
In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
Next Click OK, then Apply button and then OK to exit the Internet Properties page.
* MVPS Hosts file (http://mvps.org/winhelp2002/hosts.htm) replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.
* Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
Here (http://www.mozilla.org/products/firefox/)
* Take a good look at the following suggestions for malware prevention by reading Tony Klein’s article 'How Did I Get Infected In The First Place'
Here (http://forums.spywareinfo.com/index.php?showtopic=60955)
Thank you for your patience, and performing all of the procedures requested.
Rorschach112
2008-05-04, 19:27
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help.
Note: If it has been five days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.
If it has been less than five days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required.