Page 1 of 2 12 LastLast
Results 1 to 10 of 19

Thread: win32.downloader (possibly)

  1. #1
    Member
    Join Date
    Jun 2013
    Posts
    31

    Default win32.downloader (possibly)

    Hi there. Thanks for your help beforehand. I have done numerous scans with spybot and have got it down to two bits of malware that I can't get rid of; one of which was browser cache and (I think!) the other was a driver malware, but could be wrong; Hopefully it is in the logs. As you can gather from the title one of the malware was win32.downloader, which I have (along with all the other entries, apart from the two previously mentioned) got rid of. The reason I think it might be win32.downloader is before I went online I removed the Microsoft security essentials virus checker. The symptoms are: that the hard disk periodly thrashes sparodically for a number of seconds, the program history in the start menu has been removed and I had a report of virtual memory running out.

    Please find dds.txt and aswMBR.txt below and attach.txt attached. Thanks

    DDS (Ver_2012-11-20.01) - NTFS_x86
    Internet Explorer: 8.0.6001.18702
    Run by severin at 14:38:36 on 2014-03-05
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.958.551 [GMT 0:00]
    .
    .
    ============== Running Processes ================
    .
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
    C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    C:\WINDOWS\system32\svchost.exe -k NetworkService
    C:\WINDOWS\system32\svchost.exe -k LocalService
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://www.google.co.uk/
    BHO: Adobe PDF Reader Link Helper: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
    BHO: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - LocalServer32 - <no file>
    BHO: CIEDownloadManager Object: {C9F97205-62A3-41F2-9F2C-D99392F882EB} - LocalServer32 - <no file>
    uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
    uRun: [AdobeBridge] <no file>
    mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
    mRun: [SoundMan] SOUNDMAN.EXE
    mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
    mRun: [SDTray] "c:\program files\spybot - search & destroy 2\SDTray.exe"
    mRunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallation-feedback-appf?lic=NFVZOVgtTlNWVkwtTzRCWlEtUUlNQ0wtUVREQ0gtNElKTUg"&"inst=NzctNTA2MzUzNzYwLVhPMTArMi1RSVgxKzQtWDIwMTArMi1WSVAxMCsxLUxJQysyLVNQMSsxLVNVUCs0LUZMMTArMS1TUDFTNCsxLUREVCsyNDI5OS1ERDEwRisxLVNUMTBGQVBQKzE"&"prod=90"&"ver=10.0.1416
    dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
    uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
    mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1
    mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    .
    INFO: HKCU has more than 50 listed domains.
    If you wish to scan all of them, select the 'Force scan all domains' option.
    .
    .
    INFO: HKLM has more than 50 listed domains.
    If you wish to scan all of them, select the 'Force scan all domains' option.
    .
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    TCP: NameServer = 194.168.4.100 194.168.8.100
    TCP: Interfaces\{5D9AABCE-6BF6-430B-A590-31E920E8400F} : DHCPNameServer = 194.168.4.100 194.168.8.100
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - <orphaned>
    Notify: AtiExtEvent - Ati2evxx.dll
    Notify: SDWinLogon - SDWinLogon.dll
    AppInit_DLLs= c:\progra~1\kasper~1\kasper~1.0\adialhk.dll
    Hosts: 127.0.0.1 www.spywareinfo.com
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath -
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-11-30 64288]
    R2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\spybot - search & destroy 2\SDUpdSvc.exe [2014-3-4 1042272]
    R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2007-4-4 24344]
    S2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\spybot - search & destroy 2\SDFSSvc.exe [2014-3-4 3921880]
    S2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files\spybot - search & destroy 2\SDWSCSvc.exe [2014-3-4 171416]
    S3 KLIF;KLIF;\??\c:\windows\system32\drivers\klif.sys --> c:\windows\system32\drivers\klif.sys [?]
    S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\lavasoft\ad-aware\kernexplorer.sys --> c:\program files\lavasoft\ad-aware\KernExplorer.sys [?]
    .
    =============== File Associations ===============
    .
    FileExt: .js: jsfile="c:\program files\adobe\adobe dreamweaver cs4\Dreamweaver.exe","%1"
    ShellExec: dreamweaver.exe: Open="c:\program files\adobe\adobe dreamweaver cs4\dreamweaver.exe", "%1"
    .
    =============== Created Last 30 ================
    .
    2014-03-05 14:28:08 -------- d-----w- c:\documents and settings\severin\local settings\application data\PCHealth
    2014-03-04 17:31:00 -------- d-----w- C:\01d9e00a321d0f373641
    2014-03-04 16:41:56 25088 -c----w- c:\windows\system32\dllcache\hidparse.sys
    2014-03-04 16:41:56 14976 -c----w- c:\windows\system32\dllcache\usbscan.sys
    2014-03-04 16:40:13 18968 ----a-w- c:\windows\system32\sdnclean.exe
    2014-03-04 16:39:57 -------- d-----w- c:\program files\Spybot - Search & Destroy 2
    2014-03-04 16:39:22 60160 -c----w- c:\windows\system32\dllcache\usbaudio.sys
    2014-03-04 16:39:22 123008 -c----w- c:\windows\system32\dllcache\usbvideo.sys
    2014-03-04 16:38:05 5376 -c----w- c:\windows\system32\dllcache\usbd.sys
    2014-03-04 16:38:05 32384 -c----w- c:\windows\system32\dllcache\usbccgp.sys
    2014-03-04 16:38:05 30336 -c----w- c:\windows\system32\dllcache\usbehci.sys
    2014-03-04 16:38:05 144128 -c----w- c:\windows\system32\dllcache\usbport.sys
    2014-03-04 14:37:06 -------- d-----w- c:\windows\system32\MRT
    2014-03-04 14:32:57 14592 -c--a-w- c:\windows\system32\dllcache\kbdhid.sys
    2014-03-04 14:32:57 14592 ----a-w- c:\windows\system32\drivers\kbdhid.sys
    .
    ==================== Find3M ====================
    .
    2014-03-04 17:21:47 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2014-03-04 17:21:47 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
    2014-02-05 23:26:52 920064 ----a-w- c:\windows\system32\wininet.dll
    2014-02-05 23:26:43 43520 ----a-w- c:\windows\system32\licmgr10.dll
    2014-02-05 23:26:42 1469440 ------w- c:\windows\system32\inetcpl.cpl
    2014-02-05 23:26:37 18944 ----a-w- c:\windows\system32\corpol.dll
    2014-02-05 22:24:05 385024 ----a-w- c:\windows\system32\html.iec
    2014-01-19 07:32:23 231584 ------w- c:\windows\system32\MpSigStub.exe
    2014-01-04 03:13:05 420864 ----a-w- c:\windows\system32\vbscript.dll
    .
    ============= FINISH: 14:39:23.39 ===============

    aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
    Run date: 2014-03-05 14:41:48
    -----------------------------
    14:41:48.671 OS Version: Windows 5.1.2600 Service Pack 3
    14:41:48.671 Number of processors: 2 586 0x409
    14:41:48.671 ComputerName: SEVERIN-BE38D64 UserName: severin
    14:41:49.062 Initialize success
    14:43:48.171 AVAST engine defs: 14030401
    14:45:01.546 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP5T0L0-b
    14:45:01.546 Disk 0 Vendor: HDS728080PLAT20 PF2OA2AA Size: 78533MB BusType: 3
    14:45:01.703 Disk 0 MBR read successfully
    14:45:01.703 Disk 0 MBR scan
    14:45:01.750 Disk 0 Windows XP default MBR code
    14:45:01.765 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 78520 MB offset 63
    14:45:01.765 Disk 0 scanning sectors +160810650
    14:45:01.937 Disk 0 scanning C:\WINDOWS\system32\drivers
    14:45:13.343 Service scanning
    14:45:38.140 Modules scanning
    14:46:14.250 Disk 0 trace - called modules:
    14:46:14.250 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys amdide.sys PCIIDEX.SYS
    14:46:14.250 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86114ab8]
    14:46:14.265 3 CLASSPNP.SYS[f75f0fd7] -> nt!IofCallDriver -> \Device\0000005e[0x8612c9e8]
    14:46:14.265 5 ACPI.sys[f7487620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP5T0L0-b[0x8612cd98]
    14:46:15.375 AVAST engine scan C:\WINDOWS
    14:46:21.343 AVAST engine scan C:\WINDOWS\system32
    14:49:19.812 AVAST engine scan C:\WINDOWS\system32\drivers
    14:49:38.453 AVAST engine scan C:\Documents and Settings\severin
    14:52:36.203 AVAST engine scan C:\Documents and Settings\All Users
    14:53:16.375 Scan finished successfully
    14:54:54.671 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\severin\Desktop\MBR.dat"
    14:54:54.671 The log file has been saved successfully to "C:\Documents and Settings\severin\Desktop\aswMBR.txt"
    Attached Files Attached Files

  2. #2
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    Hi and welcome

    It's going to be difficult to clean this computer and keep it clean. In a couple of weeks Microsoft will discontinue support for XP machines.
    Upgrading the entire Operating system is a good choice because the antimalware/virus protection programs can't stop or wont be able to stop the infections, these applications cannot plug holes in a vulnerable version of windows.
    I don't think there will be any stopping XP systems from being exploited, as hackers are already jumping on systems and taking over.

    Please read over the below links with choices that are available.

    http://forums.whatthetech.com/index....owtopic=127901
    http://forums.pcpitstop.com/index.ph...heir-machines/


    Let's continue here and see what we can do.




    Please download and run RogueKiller 32 Bit to your desktop.

    RogueKiller 64 Bit <---use this one for 64 bit systems

    Which system am I using?

    Quit all running programs.

    For Windows XP, double-click to start.
    For Vista or Windows 7-8, do a right-click on the program, select Run as Administrator to start, & when prompted Allow to run.


    Click Scan to scan the system.
    When the scan completes > Close out the program > Don't Fix anything!

    Post back the report which should be located on your desktop.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    -AdwCleaner-by Xplode

    Click on this link to download : ADWCleaner
    Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop.

    Do not click on any links in the top Advertisment.


    • Close all open programs and internet browsers.
    • Double click on AdwCleaner.exe to run the tool.
    • Click on Scan.
    • After the scan is complete click on "Clean"
    • Confirm each time with Ok.
    • Your computer will be rebooted automatically. A text file will open after the restart.
    • Please post the content of that logfile with your next answer.
    • You can find the logfile at C:\AdwCleaner[S1].txt as well.


    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



    Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.


    ~~~~~~~~~~~~~~~~~~~~~~`
    Please post:
    RogueKiller log
    AdwCleaner.txt
    JRT.txt
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  3. #3
    Member
    Join Date
    Jun 2013
    Posts
    31

    Default thanks

    Hi there Juliet. please find the logs as requested. Did the scan with roguekiller and did not fix anything. Did the scan with adwcleaner, but forgot to close IE, but I presume adwcleaner did it itself because it came up with an alert saying it was going to do that. Did another scan but the report did not have any entries so that's why I presume it worked. ran jrt and did scan; it opened up a window for my documents which I closed because I thought it might have stopped jrt from running, but later jrt reported that it could not open a document in my documents, I think.

    Here are the logs:

    RogueKiller V8.8.10 [Feb 28 2014] by Adlice Software
    mail : http://www.adlice.com/contact/
    Feedback : http://forum.adlice.com
    Website : http://www.adlice.com/softwares/roguekiller/
    Blog : http://www.adlice.com

    Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
    Started in : Normal mode
    User : severin [Admin rights]
    Mode : Scan -- Date : 03/06/2014 13:22:55
    | ARK || FAK || MBR |

    ¤¤¤ Bad processes : 0 ¤¤¤

    ¤¤¤ Registry Entries : 1 ¤¤¤
    [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

    ¤¤¤ Scheduled tasks : 0 ¤¤¤

    ¤¤¤ Startup Entries : 0 ¤¤¤

    ¤¤¤ Web browsers : 0 ¤¤¤

    ¤¤¤ Browser Addons : 0 ¤¤¤

    ¤¤¤ Particular Files / Folders: ¤¤¤

    ¤¤¤ Driver : [LOADED] ¤¤¤

    ¤¤¤ External Hives: ¤¤¤

    ¤¤¤ Infection : ¤¤¤

    ¤¤¤ HOSTS File: ¤¤¤
    --> %SystemRoot%\System32\drivers\etc\hosts


    127.0.0.1 localhost
    127.0.0.1 www.007guard.com
    127.0.0.1 007guard.com
    127.0.0.1 008i.com
    127.0.0.1 www.008k.com
    127.0.0.1 008k.com
    127.0.0.1 www.00hq.com
    127.0.0.1 00hq.com
    127.0.0.1 010402.com
    127.0.0.1 www.032439.com
    127.0.0.1 032439.com
    127.0.0.1 www.0scan.com
    127.0.0.1 0scan.com
    127.0.0.1 1000gratisproben.com
    127.0.0.1 www.1000gratisproben.com
    127.0.0.1 1001namen.com
    127.0.0.1 www.1001namen.com
    127.0.0.1 100888290cs.com
    127.0.0.1 www.100888290cs.com
    127.0.0.1 www.100sexlinks.com
    [...]


    ¤¤¤ MBR Check: ¤¤¤

    +++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) HDS728080PLAT20 +++++
    --- User ---
    [MBR] d8555d1a7f98d84b841b2a7b93cb76ed
    [BSP] 8ed334f39b50d8b8e8082ef9d1e35016 : Windows XP MBR Code
    Partition table:
    0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 78520 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!

    Finished : << RKreport[0]_S_03062014_132255.txt >>




    # AdwCleaner v3.020 - Report created 06/03/2014 at 13:28:00
    # Updated 27/02/2014 by Xplode
    # Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
    # Username : severin - SEVERIN-BE38D64
    # Running from : C:\Documents and Settings\severin\Desktop\AdwCleaner.exe
    # Option : Clean

    ***** [ Services ] *****


    ***** [ Files / Folders ] *****

    Folder Deleted : C:\Documents and Settings\All Users\Application Data\NCH Software
    Folder Deleted : C:\Program Files\Conduit
    Folder Deleted : C:\Documents and Settings\severin\Application Data\PriceGong
    File Deleted : C:\Documents and Settings\severin\Application Data\Mozilla\Firefox\Profiles\x6u30xdu.default\searchplugins\MyStart Search.xml
    File Deleted : C:\Documents and Settings\severin\Application Data\Mozilla\Firefox\Profiles\x6u30xdu.default\user.js

    ***** [ Shortcuts ] *****


    ***** [ Registry ] *****

    Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla
    Key Deleted : HKLM\SOFTWARE\Classes\Conduit.Engine
    Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2878731
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
    Key Deleted : HKCU\Software\IM
    Key Deleted : HKCU\Software\ImInstaller
    Key Deleted : HKCU\Software\InstallCore
    Key Deleted : HKCU\Software\NCH Software
    Key Deleted : HKCU\Software\PriceGong
    Key Deleted : HKCU\Software\SmartBar
    Key Deleted : HKLM\Software\Conduit
    Key Deleted : HKLM\Software\Driver-Soft
    Key Deleted : HKLM\Software\ImInstaller

    ***** [ Browsers ] *****

    -\\ Internet Explorer v8.0.6001.18702


    -\\ Mozilla Firefox v21.0 (en-US)

    *************************

    AdwCleaner[R0].txt - [2103 octets] - [06/03/2014 13:26:31]
    AdwCleaner[S0].txt - [2072 octets] - [06/03/2014 13:28:00]

    ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2132 octets] ##########
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Junkware Removal Tool (JRT) by Thisisu
    Version: 6.1.2 (02.20.2014:1)
    OS: Microsoft Windows XP x86
    Ran by severin on 06/03/2014 at 13:41:19.09
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




    ~~~ Services



    ~~~ Registry Values

    Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
    Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL



    ~~~ Registry Keys



    ~~~ Files



    ~~~ Folders





    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Scan was completed on 06/03/2014 at 13:46:41.56
    End of JRT log
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  4. #4
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    Please download Farbar Recovery Scan Tool

    (use correct version for your system.....Which system am I using?)
    and Tutorial http://www.geekstogo.com/forum/topic...ery-scan-tool/



    Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
    • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will produce a log called FRST.txt in the same directory the tool is run from.
    • Please copy and paste log back here.
    • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  5. #5
    Member
    Join Date
    Jun 2013
    Posts
    31

    Default thanks

    Hi there again Juliet. Have done the scan. Forgot to close down browser, but did so mid-scan. Hope that hasn't caused any problems. Here are the logs:

    Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 06-03-2014
    Ran by severin (administrator) on SEVERIN-BE38D64 on 06-03-2014 14:49:46
    Running from C:\Documents and Settings\severin\Desktop
    Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: English(US)
    Internet Explorer Version 8
    Boot Mode: Normal

    The only official download link for FRST:
    Download link for 32-Bit version: http://www.bleepingcomputer.com/down...an-tool/dl/81/
    Download link for 64-Bit Version: http://www.bleepingcomputer.com/down...an-tool/dl/82/
    Download link from any site other than Bleeping Computer is unpermitted or outdated.
    See tutorial for FRST: http://www.geekstogo.com/forum/topic...ery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (ATI Technologies Inc.) C:\WINDOWS\system32\Ati2evxx.exe
    (ATI Technologies Inc.) C:\WINDOWS\system32\Ati2evxx.exe
    (Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
    (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
    (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    (Realtek Semiconductor Corp.) C:\WINDOWS\SOUNDMAN.EXE
    (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
    (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
    (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
    (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
    (Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
    (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
    (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe


    ==================== Registry (Whitelisted) ==================

    HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [61440 2010-02-10] (Advanced Micro Devices, Inc.)
    HKLM\...\Run: [SoundMan] - C:\WINDOWS\SOUNDMAN.EXE [577536 2007-04-16] (Realtek Semiconductor Corp.)
    HKLM\...\Run: [AdobeCS4ServiceManager] - C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [611712 2008-08-14] (Adobe Systems Incorporated)
    HKLM\...\Run: [SDTray] - C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
    HKLM\...\Runonce: [AvgUninstallURL] - cmd.exe /c start http://www.avg.com/ww.special-uninstallation-feedback-appf?lic=NFVZOVgtTlNWVkwtTzRCWlEtUUlNQ0wtUVREQ0gtNElKTUg"&"inst=NzctNTA2MzUzNzYwLVhPMTArMi1RSVgxKzQtWDIwMTArMi1WSVAxMCsxLUxJQysyLVNQMSsxLVNVUCs0LUZMMTArMS1TUDFTNCsxLUREVCsyNDI5OS1ERDEwRisxLVNUMTBGQVBQKzE"&"prod=90"&"ver=10.0.1416
    Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
    Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X]
    HKU\S-1-5-21-1844237615-1957994488-682003330-1004\...\Run: [AdobeBridge] - [X]
    HKU\S-1-5-21-1844237615-1957994488-682003330-1004\...\Run: [Spybot-S&D Cleaning] - C:\Program Files\Spybot - Search & Destroy 2\SDCleaner.exe [3666224 2013-09-20] (Safer-Networking Ltd.)
    AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll => C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll File Not Found

    ==================== Internet (Whitelisted) ====================

    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
    HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir...ie&ar=iesearch
    SearchScopes: HKLM - DefaultScope value is missing.
    SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search
    SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search
    BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
    BHO: CIEDownloadManager Object - {C9F97205-62A3-41F2-9F2C-D99392F882EB} - No File
    Toolbar: HKCU - &Address - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
    Toolbar: HKCU - &Links - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
    Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File
    Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
    Tcpip\Parameters: [DhcpNameServer] 194.168.4.100 194.168.8.100

    FireFox:
    ========
    FF ProfilePath: C:\Documents and Settings\severin\Application Data\Mozilla\Firefox\Profiles\x6u30xdu.default
    FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_12_0_0_70.dll ()
    FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
    FF Plugin: @microsoft.com/WPF,version=3.5 - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
    FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
    FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
    FF Plugin: @videolan.org/vlc,version=1.0.5 - C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
    FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
    FF Extension: Microsoft .NET Framework Assistant - C:\Documents and Settings\severin\Application Data\Mozilla\Firefox\Profiles\x6u30xdu.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi [2013-05-24]
    FF Extension: Adblock Plus - C:\Documents and Settings\severin\Application Data\Mozilla\Firefox\Profiles\x6u30xdu.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-05-24]
    FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
    FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
    FF HKLM\...\Firefox\Extensions: [{1E73965B-8B48-48be-9C8D-68B920ABC1C4}] - C:\Program Files\AVG\AVG10\Firefox4\

    ========================== Services (Whitelisted) =================

    S2 ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [593920 2010-02-10] ()
    R2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.)
    R2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.)
    S2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.)
    S2 DM1Service; C:\Program Files\Olympus\DeviceDetector\DM1Service.exe [X]

    ==================== Drivers (Whitelisted) ====================

    R3 ALCXWDM; C:\WINDOWS\System32\drivers\ALCXWDM.SYS [4122368 2008-09-24] (Realtek Semiconductor Corp.)
    R0 amdide; C:\WINDOWS\System32\DRIVERS\amdide.sys [9096 2007-10-12] (Advanced Micro Devices)
    S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
    R3 klim5; C:\WINDOWS\System32\DRIVERS\klim5.sys [24344 2007-04-04] (Kaspersky Lab)
    R0 Lbd; C:\WINDOWS\System32\DRIVERS\Lbd.sys [64288 2010-09-23] (Lavasoft AB)
    S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
    R3 pfc; C:\WINDOWS\System32\drivers\pfc.sys [21248 2003-09-19] (Padus, Inc.)
    S3 rtl8139; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [20992 2004-08-03] (Realtek Semiconductor Corporation)
    S4 IntelIde; No ImagePath
    S3 KLIF; \??\C:\WINDOWS\system32\drivers\klif.sys [X]
    S3 Lavasoft Kernexplorer; \??\C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys [X]
    U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
    U1 WS2IFSL;

    ==================== NetSvcs (Whitelisted) ===================


    ==================== One Month Created Files and Folders ========

    2014-03-06 14:49 - 2014-03-06 14:49 - 00008287 _____ () C:\Documents and Settings\severin\Desktop\FRST.txt
    2014-03-06 14:49 - 2014-03-06 14:49 - 00000000 ____D () C:\FRST
    2014-03-06 14:48 - 2014-03-06 14:48 - 01145344 _____ (Farbar) C:\Documents and Settings\severin\Desktop\FRST.exe
    2014-03-06 13:46 - 2014-03-06 13:46 - 00000899 _____ () C:\Documents and Settings\severin\Desktop\JRT.txt
    2014-03-06 13:41 - 2014-03-06 13:41 - 00000000 ____D () C:\WINDOWS\ERUNT
    2014-03-06 13:39 - 2014-03-06 13:39 - 01037734 _____ (Thisisu) C:\Documents and Settings\severin\Desktop\JRT.exe
    2014-03-06 13:26 - 2014-03-06 13:33 - 00000000 ____D () C:\AdwCleaner
    2014-03-06 13:25 - 2014-03-06 13:25 - 01244192 _____ () C:\Documents and Settings\severin\Desktop\AdwCleaner.exe
    2014-03-06 13:22 - 2014-03-06 13:22 - 00001878 _____ () C:\Documents and Settings\severin\Desktop\RKreport[0]_S_03062014_132255.txt
    2014-03-06 13:19 - 2014-03-06 13:26 - 00000000 ____D () C:\Documents and Settings\severin\Desktop\RK_Quarantine
    2014-03-06 13:19 - 2014-03-06 13:19 - 03819008 _____ () C:\Documents and Settings\severin\Desktop\RogueKiller.exe
    2014-03-05 15:18 - 2014-03-05 15:18 - 00004146 _____ () C:\Documents and Settings\severin\Desktop\attach.zip
    2014-03-05 15:12 - 2014-03-05 15:12 - 00009680 _____ () C:\Documents and Settings\severin\Desktop\thread.txt
    2014-03-05 14:54 - 2014-03-05 14:54 - 00001950 _____ () C:\Documents and Settings\severin\Desktop\aswMBR.txt
    2014-03-05 14:54 - 2014-03-05 14:54 - 00000512 _____ () C:\Documents and Settings\severin\Desktop\MBR.dat
    2014-03-05 14:39 - 2014-03-05 14:39 - 00020144 _____ () C:\Documents and Settings\severin\Desktop\attach.txt
    2014-03-05 14:39 - 2014-03-05 14:39 - 00006866 _____ () C:\Documents and Settings\severin\Desktop\dds.txt
    2014-03-05 14:36 - 2014-03-05 14:36 - 00000000 ____D () C:\Documents and Settings\severin\Desktop\05-03-2014
    2014-03-05 14:33 - 2014-03-05 14:34 - 00000000 ____D () C:\Program Files\ERUNT
    2014-03-05 14:33 - 2014-03-05 14:33 - 00000611 _____ () C:\Documents and Settings\severin\Desktop\NTREGOPT.lnk
    2014-03-05 14:33 - 2014-03-05 14:33 - 00000592 _____ () C:\Documents and Settings\severin\Desktop\ERUNT.lnk
    2014-03-05 14:33 - 2014-03-05 14:33 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT
    2014-03-05 14:32 - 2014-03-05 14:33 - 04745728 _____ (AVAST Software) C:\Documents and Settings\severin\Desktop\aswMBR.exe
    2014-03-05 14:32 - 2014-03-05 14:32 - 00791393 _____ (Lars Hederer ) C:\Documents and Settings\severin\Desktop\erunt-setup.exe
    2014-03-05 14:32 - 2014-03-05 14:32 - 00688992 ____R (Swearware) C:\Documents and Settings\severin\Desktop\dds.scr
    2014-03-05 14:28 - 2014-03-05 14:28 - 00000000 ____D () C:\Documents and Settings\severin\Local Settings\Application Data\PCHealth
    2014-03-04 19:47 - 2014-03-04 19:47 - 00012997 _____ () C:\WINDOWS\KB2834886.log
    2014-03-04 19:47 - 2014-03-04 19:47 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2916036$
    2014-03-04 19:47 - 2014-03-04 19:47 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2868626$
    2014-03-04 19:47 - 2014-03-04 19:47 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2834886$
    2014-03-04 19:43 - 2014-03-04 19:43 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2900986$
    2014-03-04 19:42 - 2014-03-04 19:43 - 00012787 _____ () C:\WINDOWS\KB2900986.log
    2014-03-04 19:42 - 2014-03-04 19:42 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2898715$
    2014-03-04 19:42 - 2014-03-04 19:42 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2847311$
    2014-03-04 19:40 - 2014-03-04 19:41 - 00012351 _____ () C:\WINDOWS\KB2862335.log
    2014-03-04 19:40 - 2014-03-04 19:40 - 00011693 _____ () C:\WINDOWS\KB2904266.log
    2014-03-04 19:40 - 2014-03-04 19:40 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2904266$
    2014-03-04 19:40 - 2014-03-04 19:40 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2876217$
    2014-03-04 19:40 - 2014-03-04 19:40 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2862335$
    2014-03-04 19:40 - 2014-03-04 19:40 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2845187$
    2014-03-04 19:39 - 2014-03-04 19:39 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2864063$
    2014-03-04 19:37 - 2014-03-04 19:37 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2862152$
    2014-03-04 19:34 - 2014-03-04 19:34 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2850869$
    2014-03-04 19:33 - 2014-03-04 19:33 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2876331$
    2014-03-04 19:33 - 2014-03-04 19:33 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2859537$
    2014-03-04 19:25 - 2014-03-04 19:25 - 00010943 _____ () C:\WINDOWS\KB2868038.log
    2014-03-04 19:25 - 2014-03-04 19:25 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2893294$
    2014-03-04 19:25 - 2014-03-04 19:25 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2868038$
    2014-03-04 19:24 - 2014-03-04 19:47 - 00005829 _____ () C:\WINDOWS\updspapi.log
    2014-03-04 19:24 - 2014-03-04 19:24 - 00009884 _____ () C:\WINDOWS\KB2803821-v2.log
    2014-03-04 19:24 - 2014-03-04 19:24 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2893984$
    2014-03-04 19:24 - 2014-03-04 19:24 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2803821-v2_WM9$
    2014-03-04 19:23 - 2014-03-04 19:24 - 00011800 _____ () C:\WINDOWS\KB2909921-IE8.log
    2014-03-04 19:23 - 2014-03-04 19:23 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2892075$
    2014-03-04 19:22 - 2014-03-04 19:22 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2862330$
    2014-03-04 19:20 - 2014-03-04 19:22 - 00004941 _____ () C:\WINDOWS\KB2909210-IE8.log
    2014-03-04 17:31 - 2014-03-04 17:31 - 00000000 ____D () C:\01d9e00a321d0f373641
    2014-03-04 16:55 - 2013-05-24 15:37 - 00448691 ____R () C:\WINDOWS\system32\Drivers\etc\hosts.20140304-165507.backup
    2014-03-04 16:45 - 2014-03-04 19:47 - 00018975 _____ () C:\WINDOWS\KB2916036.log
    2014-03-04 16:42 - 2014-03-04 19:47 - 00018701 _____ () C:\WINDOWS\KB2868626.log
    2014-03-04 16:42 - 2014-03-04 19:42 - 00017545 _____ () C:\WINDOWS\KB2847311.log
    2014-03-04 16:42 - 2014-03-04 19:42 - 00017012 _____ () C:\WINDOWS\KB2898715.log
    2014-03-04 16:41 - 2014-03-06 14:45 - 00000644 _____ () C:\WINDOWS\Tasks\Check for updates (Spybot - Search & Destroy).job
    2014-03-04 16:41 - 2014-03-04 19:40 - 00016023 _____ () C:\WINDOWS\KB2876217.log
    2014-03-04 16:41 - 2014-03-04 19:40 - 00015707 _____ () C:\WINDOWS\KB2845187.log
    2014-03-04 16:41 - 2014-03-04 19:39 - 00015194 _____ () C:\WINDOWS\KB2864063.log
    2014-03-04 16:41 - 2014-03-04 16:41 - 00000616 _____ () C:\WINDOWS\Tasks\Refresh immunization (Spybot - Search & Destroy).job
    2014-03-04 16:41 - 2014-03-04 16:41 - 00000446 _____ () C:\WINDOWS\Tasks\Scan the system (Spybot - Search & Destroy).job
    2014-03-04 16:41 - 2013-07-03 02:12 - 00025088 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\hidparse.sys
    2014-03-04 16:41 - 2013-07-03 01:59 - 00014976 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbscan.sys
    2014-03-04 16:40 - 2014-03-06 14:05 - 00065536 _____ () C:\WINDOWS\system32\config\SpybotSD.evt
    2014-03-04 16:40 - 2014-03-04 19:37 - 00015502 _____ () C:\WINDOWS\KB2862152.log
    2014-03-04 16:40 - 2014-03-04 16:40 - 00001842 _____ () C:\Documents and Settings\All Users\Start Menu\Programs\Spybot-S&D Start Center.lnk
    2014-03-04 16:40 - 2014-03-04 16:40 - 00001836 _____ () C:\Documents and Settings\All Users\Desktop\Spybot-S&D Start Center.lnk
    2014-03-04 16:40 - 2014-03-04 16:40 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy 2
    2014-03-04 16:40 - 2013-09-20 10:49 - 00018968 _____ (Safer Networking Limited) C:\WINDOWS\system32\sdnclean.exe
    2014-03-04 16:39 - 2014-03-04 19:34 - 00014673 _____ () C:\WINDOWS\KB2850869.log
    2014-03-04 16:39 - 2014-03-04 19:33 - 00015841 _____ () C:\WINDOWS\KB2859537.log
    2014-03-04 16:39 - 2014-03-04 19:33 - 00014977 _____ () C:\WINDOWS\KB2876331.log
    2014-03-04 16:39 - 2014-03-04 19:25 - 00014307 _____ () C:\WINDOWS\KB2893294.log
    2014-03-04 16:39 - 2014-03-04 19:24 - 00014732 _____ () C:\WINDOWS\KB2893984.log
    2014-03-04 16:39 - 2014-03-04 16:43 - 00000000 ____D () C:\Program Files\Spybot - Search & Destroy 2
    2014-03-04 16:39 - 2013-07-17 00:58 - 00123008 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbvideo.sys
    2014-03-04 16:39 - 2013-07-17 00:58 - 00060160 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbaudio.sys
    2014-03-04 16:38 - 2014-03-04 19:23 - 00008761 _____ () C:\WINDOWS\KB2892075.log
    2014-03-04 16:38 - 2013-08-09 00:55 - 00144128 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbport.sys
    2014-03-04 16:38 - 2013-08-09 00:55 - 00032384 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbccgp.sys
    2014-03-04 16:38 - 2013-08-09 00:55 - 00005376 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbd.sys
    2014-03-04 16:38 - 2009-03-18 11:02 - 00030336 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbehci.sys
    2014-03-04 15:21 - 2014-03-04 15:21 - 00000000 ____D () C:\Documents and Settings\severin\My Documents\CyberLink
    2014-03-04 14:37 - 2014-03-04 19:27 - 00000000 ____D () C:\WINDOWS\system32\MRT
    2014-03-04 14:35 - 2014-03-04 14:35 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2914368$
    2014-03-04 14:34 - 2014-03-04 14:35 - 00004506 _____ () C:\WINDOWS\KB2914368.log
    2014-03-04 14:32 - 2008-04-13 19:39 - 00014592 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdhid.sys
    2014-03-04 14:32 - 2008-04-13 19:39 - 00014592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdhid.sys
    2014-02-09 16:44 - 2014-02-09 16:44 - 00606080 _____ () C:\Documents and Settings\severin\My Documents\windows xp service pack 3 setup.exe
    2014-02-09 16:40 - 2014-03-04 19:47 - 00159399 _____ () C:\WINDOWS\FaxSetup.log
    2014-02-09 16:40 - 2014-03-04 19:47 - 00085185 _____ () C:\WINDOWS\ocgen.log
    2014-02-09 16:40 - 2014-03-04 19:47 - 00062930 _____ () C:\WINDOWS\tsoc.log
    2014-02-09 16:40 - 2014-03-04 19:47 - 00053511 _____ () C:\WINDOWS\comsetup.log
    2014-02-09 16:40 - 2014-03-04 19:47 - 00033551 _____ () C:\WINDOWS\ntdtcsetup.log
    2014-02-09 16:40 - 2014-03-04 19:47 - 00024443 _____ () C:\WINDOWS\iis6.log
    2014-02-09 16:40 - 2014-03-04 19:47 - 00009093 _____ () C:\WINDOWS\ocmsn.log
    2014-02-09 16:40 - 2014-03-04 19:47 - 00008052 _____ () C:\WINDOWS\msgsocm.log
    2014-02-09 16:40 - 2014-03-04 19:47 - 00001355 _____ () C:\WINDOWS\imsins.log
    2014-02-09 16:40 - 2014-03-04 19:47 - 00001355 _____ () C:\WINDOWS\imsins.BAK
    2014-02-09 16:40 - 2014-02-09 16:40 - 00000767 _____ () C:\Documents and Settings\severin\Start Menu\Programs\Internet Explorer.lnk
    2014-02-09 16:37 - 2014-03-04 14:32 - 00000116 _____ () C:\WINDOWS\setupact.log

    ==================== One Month Modified Files and Folders =======

    2014-03-06 14:49 - 2014-03-06 14:49 - 00008287 _____ () C:\Documents and Settings\severin\Desktop\FRST.txt
    2014-03-06 14:49 - 2014-03-06 14:49 - 00000000 ____D () C:\FRST
    2014-03-06 14:49 - 2013-05-25 10:42 - 00000888 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
    2014-03-06 14:48 - 2014-03-06 14:48 - 01145344 _____ (Farbar) C:\Documents and Settings\severin\Desktop\FRST.exe
    2014-03-06 14:46 - 2010-03-01 08:48 - 02062302 _____ () C:\WINDOWS\WindowsUpdate.log
    2014-03-06 14:45 - 2014-03-04 16:41 - 00000644 _____ () C:\WINDOWS\Tasks\Check for updates (Spybot - Search & Destroy).job
    2014-03-06 14:45 - 2013-05-25 10:42 - 00000884 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
    2014-03-06 14:45 - 2010-03-01 08:11 - 00000159 _____ () C:\WINDOWS\wiadebug.log
    2014-03-06 14:45 - 2010-03-01 08:11 - 00000050 _____ () C:\WINDOWS\wiaservc.log
    2014-03-06 14:44 - 2010-03-01 08:53 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
    2014-03-06 14:05 - 2014-03-04 16:40 - 00065536 _____ () C:\WINDOWS\system32\config\SpybotSD.evt
    2014-03-06 14:05 - 2010-08-04 13:25 - 00524288 _____ () C:\WINDOWS\system32\config\ACEEvent.evt
    2014-03-06 14:05 - 2010-03-01 08:54 - 00000178 ___SH () C:\Documents and Settings\severin\ntuser.ini
    2014-03-06 14:05 - 2010-03-01 08:53 - 00032190 _____ () C:\WINDOWS\SchedLgU.Txt
    2014-03-06 13:46 - 2014-03-06 13:46 - 00000899 _____ () C:\Documents and Settings\severin\Desktop\JRT.txt
    2014-03-06 13:41 - 2014-03-06 13:41 - 00000000 ____D () C:\WINDOWS\ERUNT
    2014-03-06 13:39 - 2014-03-06 13:39 - 01037734 _____ (Thisisu) C:\Documents and Settings\severin\Desktop\JRT.exe
    2014-03-06 13:33 - 2014-03-06 13:26 - 00000000 ____D () C:\AdwCleaner
    2014-03-06 13:26 - 2014-03-06 13:19 - 00000000 ____D () C:\Documents and Settings\severin\Desktop\RK_Quarantine
    2014-03-06 13:25 - 2014-03-06 13:25 - 01244192 _____ () C:\Documents and Settings\severin\Desktop\AdwCleaner.exe
    2014-03-06 13:22 - 2014-03-06 13:22 - 00001878 _____ () C:\Documents and Settings\severin\Desktop\RKreport[0]_S_03062014_132255.txt
    2014-03-06 13:21 - 2013-05-25 10:42 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
    2014-03-06 13:19 - 2014-03-06 13:19 - 03819008 _____ () C:\Documents and Settings\severin\Desktop\RogueKiller.exe
    2014-03-06 13:15 - 2010-08-04 10:36 - 00000000 ____D () C:\WINDOWS\Microsoft.NET
    2014-03-05 15:28 - 2010-08-11 10:26 - 00000000 ____D () C:\WINDOWS\system32\XPSViewer
    2014-03-05 15:27 - 2010-03-01 08:07 - 00489548 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
    2014-03-05 15:21 - 2013-05-25 10:42 - 00692616 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
    2014-03-05 15:21 - 2011-05-30 19:06 - 00071048 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
    2014-03-05 15:18 - 2014-03-05 15:18 - 00004146 _____ () C:\Documents and Settings\severin\Desktop\attach.zip
    2014-03-05 15:14 - 2010-03-17 09:13 - 00000000 ____D () C:\Program Files\WinRAR
    2014-03-05 15:12 - 2014-03-05 15:12 - 00009680 _____ () C:\Documents and Settings\severin\Desktop\thread.txt
    2014-03-05 14:54 - 2014-03-05 14:54 - 00001950 _____ () C:\Documents and Settings\severin\Desktop\aswMBR.txt
    2014-03-05 14:54 - 2014-03-05 14:54 - 00000512 _____ () C:\Documents and Settings\severin\Desktop\MBR.dat
    2014-03-05 14:39 - 2014-03-05 14:39 - 00020144 _____ () C:\Documents and Settings\severin\Desktop\attach.txt
    2014-03-05 14:39 - 2014-03-05 14:39 - 00006866 _____ () C:\Documents and Settings\severin\Desktop\dds.txt
    2014-03-05 14:36 - 2014-03-05 14:36 - 00000000 ____D () C:\Documents and Settings\severin\Desktop\05-03-2014
    2014-03-05 14:34 - 2014-03-05 14:33 - 00000000 ____D () C:\Program Files\ERUNT
    2014-03-05 14:33 - 2014-03-05 14:33 - 00000611 _____ () C:\Documents and Settings\severin\Desktop\NTREGOPT.lnk
    2014-03-05 14:33 - 2014-03-05 14:33 - 00000592 _____ () C:\Documents and Settings\severin\Desktop\ERUNT.lnk
    2014-03-05 14:33 - 2014-03-05 14:33 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT
    2014-03-05 14:33 - 2014-03-05 14:32 - 04745728 _____ (AVAST Software) C:\Documents and Settings\severin\Desktop\aswMBR.exe
    2014-03-05 14:32 - 2014-03-05 14:32 - 00791393 _____ (Lars Hederer ) C:\Documents and Settings\severin\Desktop\erunt-setup.exe
    2014-03-05 14:32 - 2014-03-05 14:32 - 00688992 ____R (Swearware) C:\Documents and Settings\severin\Desktop\dds.scr
    2014-03-05 14:28 - 2014-03-05 14:28 - 00000000 ____D () C:\Documents and Settings\severin\Local Settings\Application Data\PCHealth
    2014-03-05 14:23 - 2010-03-01 08:05 - 00150792 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
    2014-03-04 19:47 - 2014-03-04 19:47 - 00012997 _____ () C:\WINDOWS\KB2834886.log
    2014-03-04 19:47 - 2014-03-04 19:47 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2916036$
    2014-03-04 19:47 - 2014-03-04 19:47 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2868626$
    2014-03-04 19:47 - 2014-03-04 19:47 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2834886$
    2014-03-04 19:47 - 2014-03-04 19:24 - 00005829 _____ () C:\WINDOWS\updspapi.log
    2014-03-04 19:47 - 2014-03-04 16:45 - 00018975 _____ () C:\WINDOWS\KB2916036.log
    2014-03-04 19:47 - 2014-03-04 16:42 - 00018701 _____ () C:\WINDOWS\KB2868626.log
    2014-03-04 19:47 - 2014-02-09 16:40 - 00159399 _____ () C:\WINDOWS\FaxSetup.log
    2014-03-04 19:47 - 2014-02-09 16:40 - 00085185 _____ () C:\WINDOWS\ocgen.log
    2014-03-04 19:47 - 2014-02-09 16:40 - 00062930 _____ () C:\WINDOWS\tsoc.log
    2014-03-04 19:47 - 2014-02-09 16:40 - 00053511 _____ () C:\WINDOWS\comsetup.log
    2014-03-04 19:47 - 2014-02-09 16:40 - 00033551 _____ () C:\WINDOWS\ntdtcsetup.log
    2014-03-04 19:47 - 2014-02-09 16:40 - 00024443 _____ () C:\WINDOWS\iis6.log
    2014-03-04 19:47 - 2014-02-09 16:40 - 00009093 _____ () C:\WINDOWS\ocmsn.log
    2014-03-04 19:47 - 2014-02-09 16:40 - 00008052 _____ () C:\WINDOWS\msgsocm.log
    2014-03-04 19:47 - 2014-02-09 16:40 - 00001355 _____ () C:\WINDOWS\imsins.log
    2014-03-04 19:47 - 2014-02-09 16:40 - 00001355 _____ () C:\WINDOWS\imsins.BAK
    2014-03-04 19:47 - 2013-05-30 13:31 - 00049813 _____ () C:\WINDOWS\setupapi.log
    2014-03-04 19:47 - 2010-03-01 09:22 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Microsoft Help
    2014-03-04 19:43 - 2014-03-04 19:43 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2900986$
    2014-03-04 19:43 - 2014-03-04 19:42 - 00012787 _____ () C:\WINDOWS\KB2900986.log
    2014-03-04 19:42 - 2014-03-04 19:42 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2898715$
    2014-03-04 19:42 - 2014-03-04 19:42 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2847311$
    2014-03-04 19:42 - 2014-03-04 16:42 - 00017545 _____ () C:\WINDOWS\KB2847311.log
    2014-03-04 19:42 - 2014-03-04 16:42 - 00017012 _____ () C:\WINDOWS\KB2898715.log
    2014-03-04 19:41 - 2014-03-04 19:40 - 00012351 _____ () C:\WINDOWS\KB2862335.log
    2014-03-04 19:40 - 2014-03-04 19:40 - 00011693 _____ () C:\WINDOWS\KB2904266.log
    2014-03-04 19:40 - 2014-03-04 19:40 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2904266$
    2014-03-04 19:40 - 2014-03-04 19:40 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2876217$
    2014-03-04 19:40 - 2014-03-04 19:40 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2862335$
    2014-03-04 19:40 - 2014-03-04 19:40 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2845187$
    2014-03-04 19:40 - 2014-03-04 16:41 - 00016023 _____ () C:\WINDOWS\KB2876217.log
    2014-03-04 19:40 - 2014-03-04 16:41 - 00015707 _____ () C:\WINDOWS\KB2845187.log
    2014-03-04 19:40 - 2010-03-02 07:31 - 00038014 _____ () C:\WINDOWS\system32\TZLog.log
    2014-03-04 19:39 - 2014-03-04 19:39 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2864063$
    2014-03-04 19:39 - 2014-03-04 16:41 - 00015194 _____ () C:\WINDOWS\KB2864063.log
    2014-03-04 19:37 - 2014-03-04 19:37 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2862152$
    2014-03-04 19:37 - 2014-03-04 16:40 - 00015502 _____ () C:\WINDOWS\KB2862152.log
    2014-03-04 19:34 - 2014-03-04 19:34 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2850869$
    2014-03-04 19:34 - 2014-03-04 16:39 - 00014673 _____ () C:\WINDOWS\KB2850869.log
    2014-03-04 19:33 - 2014-03-04 19:33 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2876331$
    2014-03-04 19:33 - 2014-03-04 19:33 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2859537$
    2014-03-04 19:33 - 2014-03-04 16:39 - 00015841 _____ () C:\WINDOWS\KB2859537.log
    2014-03-04 19:33 - 2014-03-04 16:39 - 00014977 _____ () C:\WINDOWS\KB2876331.log
    2014-03-04 19:27 - 2014-03-04 14:37 - 00000000 ____D () C:\WINDOWS\system32\MRT
    2014-03-04 19:25 - 2014-03-04 19:25 - 00010943 _____ () C:\WINDOWS\KB2868038.log
    2014-03-04 19:25 - 2014-03-04 19:25 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2893294$
    2014-03-04 19:25 - 2014-03-04 19:25 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2868038$
    2014-03-04 19:25 - 2014-03-04 16:39 - 00014307 _____ () C:\WINDOWS\KB2893294.log
    2014-03-04 19:25 - 2010-03-02 11:05 - 85946576 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
    2014-03-04 19:24 - 2014-03-04 19:24 - 00009884 _____ () C:\WINDOWS\KB2803821-v2.log
    2014-03-04 19:24 - 2014-03-04 19:24 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2893984$
    2014-03-04 19:24 - 2014-03-04 19:24 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2803821-v2_WM9$
    2014-03-04 19:24 - 2014-03-04 19:23 - 00011800 _____ () C:\WINDOWS\KB2909921-IE8.log
    2014-03-04 19:24 - 2014-03-04 16:39 - 00014732 _____ () C:\WINDOWS\KB2893984.log
    2014-03-04 19:23 - 2014-03-04 19:23 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2892075$
    2014-03-04 19:23 - 2014-03-04 16:38 - 00008761 _____ () C:\WINDOWS\KB2892075.log
    2014-03-04 19:22 - 2014-03-04 19:22 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2862330$
    2014-03-04 19:22 - 2014-03-04 19:20 - 00004941 _____ () C:\WINDOWS\KB2909210-IE8.log
    2014-03-04 17:31 - 2014-03-04 17:31 - 00000000 ____D () C:\01d9e00a321d0f373641
    2014-03-04 17:26 - 2010-03-04 16:14 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2014-03-04 16:43 - 2014-03-04 16:39 - 00000000 ____D () C:\Program Files\Spybot - Search & Destroy 2
    2014-03-04 16:41 - 2014-03-04 16:41 - 00000616 _____ () C:\WINDOWS\Tasks\Refresh immunization (Spybot - Search & Destroy).job
    2014-03-04 16:41 - 2014-03-04 16:41 - 00000446 _____ () C:\WINDOWS\Tasks\Scan the system (Spybot - Search & Destroy).job
    2014-03-04 16:40 - 2014-03-04 16:40 - 00001842 _____ () C:\Documents and Settings\All Users\Start Menu\Programs\Spybot-S&D Start Center.lnk
    2014-03-04 16:40 - 2014-03-04 16:40 - 00001836 _____ () C:\Documents and Settings\All Users\Desktop\Spybot-S&D Start Center.lnk
    2014-03-04 16:40 - 2014-03-04 16:40 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy 2
    2014-03-04 15:46 - 2010-03-04 13:15 - 00002311 _____ () C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader 8.lnk
    2014-03-04 15:37 - 2010-08-04 10:31 - 00000000 ____D () C:\Program Files\Windows Live
    2014-03-04 15:34 - 2010-08-04 10:31 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Windows Live
    2014-03-04 15:28 - 2013-05-24 17:23 - 00065536 _____ () C:\WINDOWS\system32\config\TuneUp.evt
    2014-03-04 15:28 - 2013-05-24 14:33 - 00000000 ____D () C:\Spybot - Search & Destroy
    2014-03-04 15:26 - 2010-03-12 16:00 - 00000000 ____D () C:\Program Files\CyberLink
    2014-03-04 15:23 - 2013-05-24 17:44 - 00001945 _____ () C:\WINDOWS\epplauncher.mif
    2014-03-04 15:22 - 2013-05-25 10:42 - 00000000 ____D () C:\Documents and Settings\severin\Local Settings\Application Data\Google
    2014-03-04 15:21 - 2014-03-04 15:21 - 00000000 ____D () C:\Documents and Settings\severin\My Documents\CyberLink
    2014-03-04 14:57 - 2010-11-30 15:13 - 00000000 ____D () C:\Program Files\AVG
    2014-03-04 14:50 - 2010-03-04 13:15 - 00000000 ____D () C:\Documents and Settings\severin\Local Settings\Application Data\Adobe
    2014-03-04 14:50 - 2010-03-02 09:51 - 00000000 ____D () C:\Documents and Settings\severin\Application Data\Adobe
    2014-03-04 14:35 - 2014-03-04 14:35 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2914368$
    2014-03-04 14:35 - 2014-03-04 14:34 - 00004506 _____ () C:\WINDOWS\KB2914368.log
    2014-03-04 14:32 - 2014-02-09 16:37 - 00000116 _____ () C:\WINDOWS\setupact.log
    2014-03-04 14:32 - 2004-08-17 00:49 - 00013646 _____ () C:\WINDOWS\system32\wpa.dbl
    2014-02-09 16:44 - 2014-02-09 16:44 - 00606080 _____ () C:\Documents and Settings\severin\My Documents\windows xp service pack 3 setup.exe
    2014-02-09 16:40 - 2014-02-09 16:40 - 00000767 _____ () C:\Documents and Settings\severin\Start Menu\Programs\Internet Explorer.lnk
    2014-02-06 03:54 - 2004-08-04 00:56 - 00174592 ____N (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
    2014-02-06 03:54 - 2004-08-04 00:56 - 00174592 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ie4uinit.exe
    2014-02-05 23:26 - 2013-05-24 18:42 - 00522240 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\jsdbgui.dll
    2014-02-05 23:26 - 2010-07-27 06:51 - 00743424 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iedvtool.dll
    2014-02-05 23:26 - 2010-03-02 11:04 - 11113472 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ieframe.dll
    2014-02-05 23:26 - 2010-03-02 11:04 - 02006016 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iertutil.dll
    2014-02-05 23:26 - 2010-03-02 11:04 - 00630272 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msfeeds.dll
    2014-02-05 23:26 - 2010-03-02 11:04 - 00247808 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ieproxy.dll
    2014-02-05 23:26 - 2010-03-02 11:04 - 00055296 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msfeedsbs.dll
    2014-02-05 23:26 - 2010-03-02 11:04 - 00012800 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\xpshims.dll
    2014-02-05 23:26 - 2010-03-01 08:47 - 00759296 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\vgx.dll
    2014-02-05 23:26 - 2009-03-08 04:39 - 11113472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
    2014-02-05 23:26 - 2009-03-08 04:32 - 02006016 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
    2014-02-05 23:26 - 2009-03-08 04:32 - 00630272 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
    2014-02-05 23:26 - 2009-03-08 04:31 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeedsbs.dll
    2014-02-05 23:26 - 2004-08-04 00:56 - 06021120 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mshtml.dll
    2014-02-05 23:26 - 2004-08-04 00:56 - 06021120 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
    2014-02-05 23:26 - 2004-08-04 00:56 - 01469440 ____N (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
    2014-02-05 23:26 - 2004-08-04 00:56 - 01469440 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\inetcpl.cpl
    2014-02-05 23:26 - 2004-08-04 00:56 - 01216000 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\urlmon.dll
    2014-02-05 23:26 - 2004-08-04 00:56 - 01216000 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
    2014-02-05 23:26 - 2004-08-04 00:56 - 00920064 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wininet.dll
    2014-02-05 23:26 - 2004-08-04 00:56 - 00920064 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
    2014-02-05 23:26 - 2004-08-04 00:56 - 00611840 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mstime.dll
    2014-02-05 23:26 - 2004-08-04 00:56 - 00611840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstime.dll
    2014-02-05 23:26 - 2004-08-04 00:56 - 00387584 ____N (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
    2014-02-05 23:26 - 2004-08-04 00:56 - 00387584 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iedkcs32.dll
    2014-02-05 23:26 - 2004-08-04 00:56 - 00206848 ____N (Microsoft Corporation) C:\WINDOWS\system32\occache.dll
    2014-02-05 23:26 - 2004-08-04 00:56 - 00206848 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\occache.dll
    2014-02-05 23:26 - 2004-08-04 00:56 - 00184320 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iepeers.dll
    2014-02-05 23:26 - 2004-08-04 00:56 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
    2014-02-05 23:26 - 2004-08-04 00:56 - 00105984 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\url.dll
    2014-02-05 23:26 - 2004-08-04 00:56 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\url.dll
    2014-02-05 23:26 - 2004-08-04 00:56 - 00067072 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mshtmled.dll
    2014-02-05 23:26 - 2004-08-04 00:56 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
    2014-02-05 23:26 - 2004-08-04 00:56 - 00043520 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\licmgr10.dll
    2014-02-05 23:26 - 2004-08-04 00:56 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\licmgr10.dll
    2014-02-05 23:26 - 2004-08-04 00:56 - 00025600 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\jsproxy.dll
    2014-02-05 23:26 - 2004-08-04 00:56 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
    2014-02-05 23:26 - 2004-08-04 00:56 - 00018944 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\corpol.dll
    2014-02-05 23:26 - 2004-08-04 00:56 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\corpol.dll
    2014-02-05 22:24 - 2004-08-03 22:59 - 00385024 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec

    Some content of TEMP:
    ====================
    C:\Documents and Settings\severin\Local Settings\Temp\ntdll_dump.dll
    C:\Documents and Settings\severin\Local Settings\Temp\ose00000.exe
    C:\Documents and Settings\severin\Local Settings\Temp\Quarantine.exe


    ==================== Bamital & volsnap Check =================

    C:\WINDOWS\explorer.exe => MD5 is legit
    C:\WINDOWS\system32\winlogon.exe => MD5 is legit
    C:\WINDOWS\system32\svchost.exe => MD5 is legit
    C:\WINDOWS\system32\services.exe => MD5 is legit
    C:\WINDOWS\system32\User32.dll => MD5 is legit
    C:\WINDOWS\system32\userinit.exe => MD5 is legit
    C:\WINDOWS\system32\rpcss.dll => MD5 is legit
    C:\WINDOWS\system32\Drivers\volsnap.sys => MD5 is legit

    ==================== End Of Log ============================

    Additional scan result of Farbar Recovery Scan Tool (x86) Version: 06-03-2014
    Ran by severin at 2014-03-06 14:50:27
    Running from C:\Documents and Settings\severin\Desktop
    Boot Mode: Normal
    ==========================================================


    ==================== Security Center ========================


    ==================== Installed Programs ======================

    Adobe AIR (HKLM\...\Adobe AIR) (Version: 2.0.4.13090 - Adobe Systems Inc.)
    Adobe AIR (Version: 2.0.4.13090 - Adobe Systems Inc.) Hidden
    Adobe Anchor Service CS4 (Version: 2.0 - Adobe Systems Incorporated) Hidden
    Adobe Bridge CS4 (Version: 3 - Adobe Systems Incorporated) Hidden
    Adobe CMaps CS4 (Version: 2.0 - Adobe Systems Incorporated) Hidden
    Adobe CSI CS4 (Version: 1 - Adobe Systems Incorporated) Hidden
    Adobe Default Language CS4 (Version: 2.0 - Adobe Systems Incorporated) Hidden
    Adobe Device Central CS4 (Version: 2 - Adobe Systems Incorporated) Hidden
    Adobe Dreamweaver CS4 (HKLM\...\Adobe_acce07fd2c8fe7f9e3f26243e626578) (Version: 10.0 - Adobe Systems Incorporated)
    Adobe Dreamweaver CS4 (Version: 10.0 - Adobe Systems Incorporated) Hidden
    Adobe ExtendScript Toolkit CS4 (Version: 3.0.0 - Adobe Systems Incorporated) Hidden
    Adobe Extension Manager CS4 (Version: 2.0 - Adobe Systems Incorporated) Hidden
    Adobe Flash Player 12 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 12.0.0.70 - Adobe Systems Incorporated)
    Adobe Flash Player 12 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 12.0.0.70 - Adobe Systems Incorporated)
    Adobe Output Module (Version: 2.0 - Adobe Systems Incorporated) Hidden
    Adobe PDF Library Files CS4 (Version: 9.0 - Adobe Systems Incorporated) Hidden
    Adobe Premiere Pro (HKLM\...\{084709F7-38C5-4609-B55F-2417939315EB}) (Version: 7.0 - Adobe Systems, Inc.)
    Adobe Reader 8.2.4 (HKLM\...\{AC76BA86-7AD7-1033-7B44-A82000000003}) (Version: 8.2.4 - Adobe Systems Incorporated)
    Adobe Search for Help (Version: 1.0 - Adobe Systems Incorporated) Hidden
    Adobe Service Manager Extension (Version: 1.0 - Adobe Systems Incorporated) Hidden
    Adobe Setup (Version: 2.0 - Adobe Systems Incorporated) Hidden
    Adobe Type Support CS4 (Version: 9.0 - Adobe Systems Incorporated) Hidden
    Adobe Update Manager CS4 (Version: 6.0.0 - Adobe Systems Incorporated) Hidden
    Adobe XMP Panels CS4 (Version: 2.0 - Adobe Systems Incorporated) Hidden
    ATI - Software Uninstall Utility (HKLM\...\All ATI Software) (Version: 6.14.10.1022 - )
    ATI Catalyst Control Center (HKLM\...\{055EE59D-217B-43A7-ABFF-507B966405D8}) (Version: 2.010.0210.2338 - )
    ATI Catalyst Install Manager (HKLM\...\{D32E70CD-819B-6196-0319-42AC224A8982}) (Version: 3.0.762.0 - ATI Technologies, Inc.)
    ATI Display Driver (HKLM\...\ATI Display Driver) (Version: 8.593.100-100210a-095952E-ATI - )
    AVG 2011 (Version: 10.0.1209 - AVG Technologies) Hidden
    AVG 2011 (Version: 10.0.1382 - AVG Technologies) Hidden
    AVG 2011 (Version: 10.0.1509 - AVG Technologies) Hidden
    Catalyst Control Center - Branding (Version: 1.00.0000 - ATI) Hidden
    Catalyst Control Center Core Implementation (Version: 2010.0210.2339.42455 - ATI) Hidden
    Catalyst Control Center Graphics Full Existing (Version: 2010.0210.2339.42455 - ATI) Hidden
    Catalyst Control Center Graphics Full New (Version: 2010.0210.2339.42455 - ATI) Hidden
    Catalyst Control Center Graphics Light (Version: 2010.0210.2339.42455 - ATI) Hidden
    Catalyst Control Center Graphics Previews Common (Version: 2010.0210.2339.42455 - ATI) Hidden
    Catalyst Control Center HydraVision Full (Version: 2010.0210.2339.42455 - ATI) Hidden
    Catalyst Control Center Localization All (Version: 2010.0210.2339.42455 - ATI) Hidden
    CCC Help Chinese Standard (Version: 2010.0210.2338.42455 - ATI) Hidden
    CCC Help Chinese Traditional (Version: 2010.0210.2338.42455 - ATI) Hidden
    CCC Help Czech (Version: 2010.0210.2338.42455 - ATI) Hidden
    CCC Help Danish (Version: 2010.0210.2338.42455 - ATI) Hidden
    CCC Help Dutch (Version: 2010.0210.2338.42455 - ATI) Hidden
    CCC Help English (Version: 2010.0210.2338.42455 - ATI) Hidden
    CCC Help Finnish (Version: 2010.0210.2338.42455 - ATI) Hidden
    CCC Help French (Version: 2010.0210.2338.42455 - ATI) Hidden
    CCC Help German (Version: 2010.0210.2338.42455 - ATI) Hidden
    CCC Help Greek (Version: 2010.0210.2338.42455 - ATI) Hidden
    CCC Help Hungarian (Version: 2010.0210.2338.42455 - ATI) Hidden
    CCC Help Italian (Version: 2010.0210.2338.42455 - ATI) Hidden
    CCC Help Japanese (Version: 2010.0210.2338.42455 - ATI) Hidden
    CCC Help Korean (Version: 2010.0210.2338.42455 - ATI) Hidden
    CCC Help Norwegian (Version: 2010.0210.2338.42455 - ATI) Hidden
    CCC Help Polish (Version: 2010.0210.2338.42455 - ATI) Hidden
    CCC Help Portuguese (Version: 2010.0210.2338.42455 - ATI) Hidden
    CCC Help Russian (Version: 2010.0210.2338.42455 - ATI) Hidden
    CCC Help Spanish (Version: 2010.0210.2338.42455 - ATI) Hidden
    CCC Help Swedish (Version: 2010.0210.2338.42455 - ATI) Hidden
    CCC Help Thai (Version: 2010.0210.2338.42455 - ATI) Hidden
    CCC Help Turkish (Version: 2010.0210.2338.42455 - ATI) Hidden
    ccc-core-preinstall (Version: 2010.0210.2339.42455 - ATI) Hidden
    ccc-core-static (Version: 2010.0210.2339.42455 - ATI) Hidden
    ccc-utility (Version: 2010.0210.2339.42455 - ATI) Hidden
    Connect (Version: 1.0.0.1 - Adobe Systems Incorporated) Hidden
    ERUNT 1.1j (HKLM\...\ERUNT_is1) (Version: - Lars Hederer)
    Google Update Helper (Version: 1.3.22.5 - Google Inc.) Hidden
    ImgBurn (HKLM\...\ImgBurn) (Version: 2.5.0.0 - LIGHTNING UK!)
    kuler (Version: 2.0 - Adobe Systems Incorporated) Hidden
    Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\...\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
    Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\...\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation)
    Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation)
    Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden
    Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden
    Microsoft Choice Guard (Version: 2.0.48.0 - Microsoft Corporation) Hidden
    Microsoft Kernel-Mode Driver Framework Feature Pack 1.9 (Version: - Microsoft Corporation) Hidden
    Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
    Microsoft Office 2007 Service Pack 3 (SP3) (Version: - Microsoft) Hidden
    Microsoft Office Excel MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
    Microsoft Office Home and Student 2007 (HKLM\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
    Microsoft Office Home and Student 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Live Add-in 1.5 (HKLM\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
    Microsoft Office OneNote MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office PowerPoint MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Project 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-003B-0000-0000-0000000FF1CE}_PRJPRO_{8446EB22-A746-46DC-B1BD-E0DFA1F3CDDA}) (Version: - Microsoft)
    Microsoft Office Project 2007 Service Pack 3 (SP3) (Version: - Microsoft) Hidden
    Microsoft Office Project MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Project Professional 2007 (HKLM\...\PRJPRO) (Version: 12.0.6612.1000 - Microsoft Corporation)
    Microsoft Office Project Professional 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Proof (Spanish) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Proofing (English) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
    Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (Version: - Microsoft) Hidden
    Microsoft Office Shared MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Shared Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Word MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Software Update for Web Folders (English) 12 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Mozilla Firefox 21.0 (x86 en-US) (HKLM\...\Mozilla Firefox 21.0 (x86 en-US)) (Version: 21.0 - Mozilla)
    MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
    MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
    Photoshop Camera Raw (Version: 5.0 - Adobe Systems Incorporated) Hidden
    Realtek AC'97 Audio (HKLM\...\{FB08F381-6533-4108-B7DD-039E11FBC27E}) (Version: 5.36 - Realtek Semiconductor Corp.)
    REALTEK GbE & FE Ethernet PCI NIC Driver (HKLM\...\{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}) (Version: 1.23.0000 - Realtek)
    Skins (Version: 2010.0210.2339.42455 - ATI) Hidden
    Spybot - Search & Destroy (HKLM\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.2.25 - Safer-Networking Ltd.)
    Suite Shared Configuration CS4 (Version: 1.0 - Adobe Systems Incorporated) Hidden
    Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-003B-0000-0000-0000000FF1CE}_PRJPRO_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
    Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation)
    Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM\...\{90120000-003B-0000-0000-0000000FF1CE}_PRJPRO_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft)
    Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft)
    Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM\...\{90120000-003B-0000-0000-0000000FF1CE}_PRJPRO_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft)
    Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft)
    Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM\...\{90120000-003B-0000-0000-0000000FF1CE}_PRJPRO_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft)
    Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft)
    Update for Windows Internet Explorer 8 (KB976662) (HKLM\...\KB976662-IE8) (Version: 1 - Microsoft Corporation)
    Update for Windows Internet Explorer 8 (KB978506) (HKLM\...\KB978506-IE8) (Version: 1 - Microsoft Corporation)
    Update for Windows Internet Explorer 8 (KB980182) (HKLM\...\KB980182-IE8) (Version: 1 - Microsoft Corporation)
    Update for Windows XP (KB2141007) (HKLM\...\KB2141007) (Version: 1 - Microsoft Corporation)
    Update for Windows XP (KB2345886) (HKLM\...\KB2345886) (Version: 1 - Microsoft Corporation)
    Update for Windows XP (KB2467659) (HKLM\...\KB2467659) (Version: 1 - Microsoft Corporation)
    Update for Windows XP (KB2541763) (HKLM\...\KB2541763) (Version: 1 - Microsoft Corporation)
    Update for Windows XP (KB2607712) (HKLM\...\KB2607712) (Version: 1 - Microsoft Corporation)
    Update for Windows XP (KB2616676-v2) (HKLM\...\KB2616676-v2) (Version: 2 - Microsoft Corporation)
    Update for Windows XP (KB2641690) (HKLM\...\KB2641690) (Version: 1 - Microsoft Corporation)
    Update for Windows XP (KB2661254-v2) (HKLM\...\KB2661254-v2) (Version: 2 - Microsoft Corporation)
    Update for Windows XP (KB2749655) (HKLM\...\KB2749655) (Version: 1 - Microsoft Corporation)
    Update for Windows XP (KB2904266) (HKLM\...\KB2904266) (Version: 1 - Microsoft Corporation)
    Update for Windows XP (KB951978) (HKLM\...\KB951978) (Version: 1 - Microsoft Corporation)
    Update for Windows XP (KB955759) (HKLM\...\KB955759) (Version: 1 - Microsoft Corporation)
    Update for Windows XP (KB961503) (HKLM\...\KB961503) (Version: 1 - Microsoft Corporation)
    Update for Windows XP (KB967715) (HKLM\...\KB967715) (Version: 1 - Microsoft Corporation)
    Update for Windows XP (KB968389) (HKLM\...\KB968389) (Version: 1 - Microsoft Corporation)
    Update for Windows XP (KB971029) (HKLM\...\KB971029) (Version: 1 - Microsoft Corporation)
    Update for Windows XP (KB971737) (HKLM\...\KB971737) (Version: 1 - Microsoft Corporation)
    Update for Windows XP (KB973687) (HKLM\...\KB973687) (Version: 1 - Microsoft Corporation)
    Update for Windows XP (KB973815) (HKLM\...\KB973815) (Version: 1 - Microsoft Corporation)
    Update for Windows XP (KB978207) (Version: 1 - Microsoft Corporation) Hidden
    Visual C++ 2008 x86 Runtime - (v9.0.30729) (Version: 9.0.30729 - Microsoft Corporation) Hidden
    Visual C++ 2008 x86 Runtime - v9.0.30729.01 (HKLM\...\{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01) (Version: 9.0.30729.01 - Microsoft Corporation)
    VLC media player 1.0.5 (HKLM\...\VLC media player) (Version: 1.0.5 - VideoLAN Team)
    WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden
    Windows Genuine Advantage Validation Tool (KB892130) (HKLM\...\KB892130) (Version: - Microsoft Corporation)
    Windows Internet Explorer 8 (HKLM\...\ie8) (Version: 20090308.140743 - Microsoft Corporation)
    Windows Live Call (Version: 14.0.8117.0416 - Microsoft Corporation) Hidden
    Windows XP Service Pack 3 (HKLM\...\Windows XP Service Pack) (Version: 20080414.031525 - Microsoft Corporation)

    ==================== Restore Points =========================

    24-05-2013 18:45:02 Software Distribution Service 3.0
    24-05-2013 21:28:36 Software Distribution Service 3.0
    24-05-2013 21:31:03 Software Distribution Service 3.0
    24-05-2013 22:00:54 Software Distribution Service 3.0
    30-05-2013 13:31:21 Software Distribution Service 3.0
    30-05-2013 13:50:07 Software Distribution Service 3.0
    09-02-2014 16:46:40 Software Distribution Service 3.0
    04-03-2014 14:34:27 Software Distribution Service 3.0
    04-03-2014 14:57:00 Removed AVG PC TuneUp
    04-03-2014 14:57:40 Removed AVG PC TuneUp Language Pack (en-US)
    04-03-2014 15:05:58 Removed Bing Bar
    04-03-2014 15:22:19 Removed Google Drive
    04-03-2014 15:37:04 Removed Windows Live Sign-in Assistant
    04-03-2014 15:37:29 Removed Windows Live Sync
    04-03-2014 15:37:59 Removed Windows Live Upload Tool
    04-03-2014 15:40:56 Removed Adobe Media Player
    04-03-2014 15:42:44 Removed Microsoft Silverlight
    04-03-2014 17:30:54 Software Distribution Service 3.0
    04-03-2014 19:16:26 Software Distribution Service 3.0
    05-03-2014 15:24:23 Software Distribution Service 3.0

    ==================== Hosts content: ==========================

    2004-08-17 00:48 - 2014-03-04 16:55 - 00450782 ____R C:\WINDOWS\system32\Drivers\etc\hosts
    127.0.0.1 localhost
    127.0.0.1 www.007guard.com
    127.0.0.1 007guard.com
    127.0.0.1 008i.com
    127.0.0.1 www.008k.com
    127.0.0.1 008k.com
    127.0.0.1 www.00hq.com
    127.0.0.1 00hq.com
    127.0.0.1 010402.com
    127.0.0.1 www.032439.com
    127.0.0.1 032439.com
    127.0.0.1 www.0scan.com
    127.0.0.1 0scan.com
    127.0.0.1 1000gratisproben.com
    127.0.0.1 www.1000gratisproben.com
    127.0.0.1 1001namen.com
    127.0.0.1 www.1001namen.com
    127.0.0.1 100888290cs.com
    127.0.0.1 www.100888290cs.com
    127.0.0.1 www.100sexlinks.com
    127.0.0.1 100sexlinks.com
    127.0.0.1 10sek.com
    127.0.0.1 www.10sek.com
    127.0.0.1 www.1-2005-search.com
    127.0.0.1 1-2005-search.com
    127.0.0.1 www.123fporn.info
    127.0.0.1 123fporn.info
    127.0.0.1 123haustiereundmehr.com
    127.0.0.1 www.123haustiereundmehr.com

    There are 1000 more lines.


    ==================== Scheduled Tasks (whitelisted) =============

    Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\WINDOWS\Tasks\Check for updates (Spybot - Search & Destroy).job => C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
    Task: C:\WINDOWS\Tasks\Refresh immunization (Spybot - Search & Destroy).job => C:\Program Files\Spybot - Search & Destroy 2\SDImmunize.exe
    Task: C:\WINDOWS\Tasks\Scan the system (Spybot - Search & Destroy).job => C:\Program Files\Spybot - Search & Destroy 2\SDScan.exe

    ==================== Loaded Modules (whitelisted) =============

    2014-03-04 16:40 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files\Spybot - Search & Destroy 2\sqlite3.dll
    2014-03-04 16:40 - 2013-05-16 10:55 - 00113496 _____ () C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl
    2014-03-04 16:40 - 2013-05-16 10:55 - 00416600 _____ () C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl
    2014-03-04 16:40 - 2013-05-16 10:55 - 00161112 _____ () C:\Program Files\Spybot - Search & Destroy 2\snlFileFormats150.bpl
    2014-03-04 16:40 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files\Spybot - Search & Destroy 2\av\BDSmartDB.dll
    2010-08-04 13:23 - 2010-08-04 13:23 - 00014848 _____ () C:\WINDOWS\assembly\GAC_MSIL\AxInterop.WBOCXLib\1.0.0.0__90ba9c70f846762e\AxInterop.WBOCXLib.dll
    2009-11-24 13:36 - 2009-11-24 13:36 - 00016384 ____R () C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll

    ==================== Alternate Data Streams (whitelisted) =========


    ==================== Safe Mode (whitelisted) ===================

    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"

    ==================== Disabled items from MSCONFIG ==============


    ==================== Faulty Device Manager Devices =============


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (03/04/2014 07:17:28 PM) (Source: HotFixInstaller) (User: )
    Description: EventType visualstudio8setup, P1 microsoft .net framework 3.0-kb2832411, P2 1033, P3 1604, P4 msi, P5 f, P6 9.0.40215.0, P7 install, P8 x86, P9 visualstudio8setup0, P10 visualstudio8setup1.

    Error: (03/04/2014 07:16:46 PM) (Source: MsiInstaller) (User: NT AUTHORITY)
    Description: Product: Microsoft .NET Framework 3.0 Service Pack 2 -- Error 1704. An installation for Microsoft .NET Framework 2.0 Service Pack 2 is currently suspended. You must undo the changes made by that installation to continue. Do you want to undo those changes?

    Error: (03/04/2014 04:42:12 PM) (Source: crypt32) (User: )
    Description: Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This operation returned because the timeout period expired.

    Error: (03/04/2014 04:38:15 PM) (Source: crypt32) (User: )
    Description: Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This operation returned because the timeout period expired.

    Error: (03/04/2014 04:38:15 PM) (Source: crypt32) (User: )
    Description: Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This operation returned because the timeout period expired.

    Error: (02/09/2014 04:47:14 PM) (Source: MsiInstaller) (User: NT AUTHORITY)
    Description: Product: Google Drive -- Error 1904. Module C:\Program Files\Google\Drive\contextmenu32.dll failed to register. HRESULT -1073741502. Contact your support personnel.

    Error: (05/24/2013 05:46:44 PM) (Source: Microsoft Security Client) (User: )
    Description: mssecurityclientmsseces.exe4.2.223.00x80508018scheduledscancmainwindow__onautoscancomplete0security essentialsNILNILNIL

    Error: (05/24/2013 05:43:48 PM) (Source: MPSampleSubmission) (User: )
    Description: mptelemetry0x80070003moaccachereset4.2.223.0unspecifiedunspecifiedunspecifiedNILNILNIL

    Error: (05/24/2013 05:21:17 PM) (Source: crypt32) (User: )
    Description: Failed auto update retrieval of third-party root certificate from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212.crt> with error: The specified server cannot perform the requested operation.

    Error: (05/24/2013 05:21:16 PM) (Source: crypt32) (User: )
    Description: Failed auto update retrieval of third-party root certificate from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212.crt> with error: This operation returned because the timeout period expired.


    System errors:
    =============
    Error: (03/06/2014 02:45:23 PM) (Source: Service Control Manager) (User: )
    Description: The Spybot-S&D 2 Security Center Service service failed to start due to the following error:
    %%1053

    Error: (03/06/2014 02:45:23 PM) (Source: Service Control Manager) (User: )
    Description: Timeout (30000 milliseconds) waiting for the Spybot-S&D 2 Security Center Service service to connect.

    Error: (03/06/2014 02:45:23 PM) (Source: Service Control Manager) (User: )
    Description: The DM1Service service failed to start due to the following error:
    %%2

    Error: (03/06/2014 01:35:16 PM) (Source: Service Control Manager) (User: )
    Description: The Spybot-S&D 2 Security Center Service service failed to start due to the following error:
    %%1053

    Error: (03/06/2014 01:35:16 PM) (Source: Service Control Manager) (User: )
    Description: Timeout (30000 milliseconds) waiting for the Spybot-S&D 2 Security Center Service service to connect.

    Error: (03/06/2014 01:35:16 PM) (Source: Service Control Manager) (User: )
    Description: The DM1Service service failed to start due to the following error:
    %%2

    Error: (03/06/2014 01:29:46 PM) (Source: Service Control Manager) (User: )
    Description: The Spybot-S&D 2 Security Center Service service failed to start due to the following error:
    %%1053

    Error: (03/06/2014 01:29:46 PM) (Source: Service Control Manager) (User: )
    Description: Timeout (30000 milliseconds) waiting for the Spybot-S&D 2 Security Center Service service to connect.

    Error: (03/06/2014 01:29:46 PM) (Source: Service Control Manager) (User: )
    Description: The DM1Service service failed to start due to the following error:
    %%2

    Error: (03/06/2014 01:11:31 PM) (Source: Service Control Manager) (User: )
    Description: The Spybot-S&D 2 Security Center Service service failed to start due to the following error:
    %%1053


    Microsoft Office Sessions:
    =========================

    ==================== Memory info ===========================

    Percentage of memory in use: 41%
    Total physical RAM: 958.48 MB
    Available physical RAM: 560.27 MB
    Total Pagefile: 2313.57 MB
    Available Pagefile: 1946.78 MB
    Total Virtual: 2047.88 MB
    Available Virtual: 1940.2 MB

    ==================== Drives ================================

    Drive c: () (Fixed) (Total:76.68 GB) (Free:53.8 GB) NTFS ==>[Drive with boot components (Windows XP)]

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows XP) (Size: 77 GB) (Disk ID: 39675003)
    Partition 1: (Active) - (Size=77 GB) - (Type=07 NTFS)

    ==================== End Of Log ============================

  6. #6
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    How is the computer behaving at the moment?


    Please Run TFC by OldTimer to clear temporary files:

    Download TFC from here http://oldtimer.geekstogo.com/TFC.exe
    and save it to your desktop.

    Close any open programs and Internet browsers.
    Double click TFC.exe to run it on XP (for Vista and Windows 7 right click and choose "Run as administrator") and once it opens click on the Start button on the lower left of the program to allow it to begin cleaning.
    Please be patient as clearing out temp files may take a while.
    Once it completes you may be prompted to restart your computer, please do so.
    Once it's finished you may delete TFC.exe from your desktop or save it for later use for the cleaning of temporary files.
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  7. #7
    Member
    Join Date
    Jun 2013
    Posts
    31

    Default thanks again

    Hi there once more Juliet. The computer seems to be running ok now; certainly, the hard disk does not seem to be periodically thrashing any more. I noticed in one of the logs that there were quite a few entries for dubious sites :( have they been removed now? I presume this is the reason for the hard disk thrashing as I'm aware of this file for networking purposes. Thanks for all your help

  8. #8
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    Thats a host file list created by SpyBot, if we delete it, you would have to start over having a new one created to cover those. So best to leave it alone.

    Let's check for remnants.


    Go here to run an online scanner from ESET.
    • Turn off the real time scanner of any existing antivirus program while performing the online scan
    • Tick the box next to YES, I accept the Terms of Use.
    • Click Start
    • When asked, allow the activeX control to install
    • Click Start
    • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
    • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
    • Click Scan
    • Wait for the scan to finish
    • When the scan completes, press the LIST OF THREATS FOUND button
    • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
    • Include the contents of this report in your next reply.
    • Press the BACK button.
    • Press Finish
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  9. #9
    Member
    Join Date
    Jun 2013
    Posts
    31

    Default Here's the eset scan log

    C:\Documents and Settings\severin\My Documents\windows xp service pack 3 setup.exe a variant of MSIL/Soft32Downloader.A potentially unwanted application

  10. #10
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    windows xp service pack 3 setup.exe
    Where did you download this from? >--Soft32Downloads?

    It came in with junk.

    We can remove this with no harm to the system.

    Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy.
    Paste this into the open notepad. save it to the Desktop as fixlist.txt
    NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
    It needs to be saved Next to the "Farbar Recovery Scan Tool" (FRST) program (If asked to overwrite existing one please allow)

    start
    C:\Documents and Settings\severin\My Documents\windows xp service pack 3 setup.exe
    Reboot:
    end
    Run FRST/FRST64 and press the Fix button just once and wait.
    If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
    When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.


    ~~~~~~~~~~~~~~~~~

    Download CKScanner by askey127 from HERE
    Important - Save it to your desktop.
    Doubleclick CKScanner.exe and click Search For Files.
    After a very short time, when the cursor hourglass disappears, click Save List To File.
    A message box will verify the file saved.
    Double-click the CKFiles.txt icon on your desktop and copy/paste the contents in your next reply.



    We Need to Diagnose a Possible Problem with WGA
    This may be preventing you from installing that service pack.
    1. Please download MGADiag and save it to your desktop.
    2. Double click the icon on your desktop.
    3. Push
    4. Push
    5. Go to Start -> Run and type in "Notepad"
    6. Go to Edit -> Paste in notepad.
    7. x out all of the numbers and letters in the line beginning with "Windows Product Key:"
    8. Copy and paste that log here.
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •