Logfile of random's system information tool 1.05 (written by random/random)
Run by Imperatore at 2009-01-18 08:23:11
Microsoft® Windows Vista™ Home Premium Service Pack 1
System drive C: has 77 GB (79%) free of 97 GB
Total RAM: 2549 MB (66% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:23:19, on 18.01.2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Imperatore\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Imperatore.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'NETZWERKDIENST')
O17 - HKLM\System\CCS\Services\Tcpip\..\{35FE57A5-398F-4E7F-A90E-529CD69C79B5}: NameServer = 85.255.114.46;85.255.112.210
O17 - HKLM\System\CCS\Services\Tcpip\..\{B6018C7A-7D19-463E-9894-131CA4573029}: NameServer = 85.255.114.46;85.255.112.210
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.46;85.255.112.210
O17 - HKLM\System\CS1\Services\Tcpip\..\{35FE57A5-398F-4E7F-A90E-529CD69C79B5}: NameServer = 85.255.114.46;85.255.112.210
O17 - HKLM\System\CS4\Services\Tcpip\Parameters: NameServer = 85.255.114.46;85.255.112.210
O17 - HKLM\System\CS4\Services\Tcpip\..\{35FE57A5-398F-4E7F-A90E-529CD69C79B5}: NameServer = 85.255.114.46;85.255.112.210
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.46;85.255.112.210
O18 - Protocol: haufereader - (no CLSID) - (no file)
O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Malware\a2service.exe
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - Unknown owner - C:\Program Files\ALDI Foto Service Nord\Common\Database\bin\fbserver.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
--
End of file - 3046 bytes
======Scheduled tasks folder======
C:\Windows\tasks\User_Feed_Synchronization-{0138F1D7-6AFF-4043-9359-9A670EDE3890}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"a-squared"=C:\Program Files\a-squared Anti-Malware\a2guard.exe [2008-10-04 2776720]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2006-11-22 815104]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2006-11-20 4018176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2008-02-11 204800]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{014ef835-dfbb-11dd-92cb-0016d3811ec5}]
shell\AutoRun\command - G:\LxSetup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{783809e3-ccca-11db-bdf9-806e6f6e6963}]
shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL D:\resycled\boot.com d:
shell\Open\command - D:\resycled\boot.com d:
======List of files/folders created in the last 1 months======
2009-01-18 08:23:11 ----D---- C:\rsit
2009-01-17 18:11:09 ----D---- C:\PerfLogs
2009-01-17 17:49:01 ----D---- C:\Program Files\a-squared Anti-Malware
2009-01-17 11:24:07 ----A---- C:\Windows\ntbtlog.txt
2009-01-17 11:20:48 ----D---- C:\Users\Imperatore\AppData\Roaming\Malwarebytes
2009-01-17 11:20:43 ----D---- C:\ProgramData\Malwarebytes
2009-01-17 11:20:43 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-01-11 19:05:53 ----D---- C:\Program Files\Trend Micro
2009-01-11 13:00:07 ----D---- C:\Users\Imperatore\AppData\Roaming\Haufe
2009-01-11 12:42:42 ----D---- C:\Users\Imperatore\AppData\Roaming\Lexware
2009-01-11 12:38:05 ----D---- C:\ProgramData\Lexware
2009-01-11 12:38:05 ----D---- C:\ProgramData\BTrieve
2009-01-11 12:36:00 ----D---- C:\ProgramData\Haufe
2009-01-11 12:33:59 ----D---- C:\Program Files\Common Files\Lexware
2009-01-11 11:19:46 ----D---- C:\Program Files\AS-Controlling
2009-01-11 11:19:40 ----D---- C:\Program Files\ASLernen
2009-01-10 19:16:09 ----D---- C:\ProgramData\Lavasoft
2009-01-10 19:16:09 ----D---- C:\Program Files\Lavasoft
2009-01-10 19:13:57 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2009-01-10 19:06:18 ----D---- C:\ProgramData\Spybot - Search & Destroy
2009-01-10 19:06:18 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-01-08 21:02:19 ----D---- C:\Users\Imperatore\AppData\Roaming\DivX
2009-01-08 21:01:24 ----D---- C:\Program Files\Common Files\PX Storage Engine
2009-01-08 21:01:10 ----D---- C:\Program Files\DivX
2009-01-08 20:13:56 ----D---- C:\Users\Imperatore\AppData\Roaming\vlc
======List of files/folders modified in the last 1 months======
2009-01-18 08:23:19 ----D---- C:\Windows\Prefetch
2009-01-18 08:23:14 ----D---- C:\Windows\Temp
2009-01-18 08:09:53 ----D---- C:\Windows\System32
2009-01-18 08:09:53 ----A---- C:\Windows\system32\PerfStringBackup.INI
2009-01-18 08:09:52 ----D---- C:\Windows\inf
2009-01-17 19:10:05 ----SHD---- C:\Windows\Installer
2009-01-17 19:10:01 ----D---- C:\Program Files\Opera
2009-01-17 19:09:54 ----D---- C:\Windows\system32\catroot2
2009-01-17 19:09:53 ----SHD---- C:\System Volume Information
2009-01-17 19:04:10 ----D---- C:\Windows\Logs
2009-01-17 18:35:10 ----D---- C:\Windows\winsxs
2009-01-17 18:31:41 ----D---- C:\Windows\Microsoft.NET
2009-01-17 18:31:38 ----RSD---- C:\Windows\assembly
2009-01-17 18:31:31 ----D---- C:\Windows\rescache
2009-01-17 18:24:45 ----D---- C:\Windows
2009-01-17 18:24:41 ----D---- C:\Windows\system32\catroot
2009-01-17 18:24:12 ----SHD---- C:\Boot
2009-01-17 18:23:43 ----ASH---- C:\Program Files\desktop.ini
2009-01-17 18:12:03 ----D---- C:\Program Files\Windows Sidebar
2009-01-17 18:12:03 ----D---- C:\Program Files\Windows Media Player
2009-01-17 18:12:03 ----D---- C:\Program Files\Windows Mail
2009-01-17 18:12:03 ----D---- C:\Program Files\Windows Collaboration
2009-01-17 18:12:03 ----D---- C:\Program Files\Windows Calendar
2009-01-17 18:12:03 ----D---- C:\Program Files\Movie Maker
2009-01-17 18:12:03 ----D---- C:\Program Files\Internet Explorer
2009-01-17 18:12:02 ----D---- C:\Program Files\Windows Photo Gallery
2009-01-17 18:12:02 ----D---- C:\Program Files\Windows Journal
2009-01-17 18:12:02 ----D---- C:\Program Files\Common Files\System
2009-01-17 18:12:01 ----D---- C:\Windows\servicing
2009-01-17 18:12:01 ----D---- C:\Windows\ehome
2009-01-17 18:12:01 ----D---- C:\Program Files\Windows Defender
2009-01-17 18:11:57 ----D---- C:\Windows\PolicyDefinitions
2009-01-17 18:11:57 ----D---- C:\Windows\MSAgent
2009-01-17 18:11:57 ----D---- C:\Windows\L2Schemas
2009-01-17 18:11:57 ----D---- C:\Windows\IME
2009-01-17 18:11:57 ----D---- C:\Windows\DigitalLocker
2009-01-17 18:11:56 ----D---- C:\Windows\system32\XPSViewer
2009-01-17 18:11:56 ----D---- C:\Windows\system32\ko-KR
2009-01-17 18:11:56 ----D---- C:\Windows\system32\en-US
2009-01-17 18:11:56 ----D---- C:\Windows\system32\de-DE
2009-01-17 18:11:56 ----D---- C:\Windows\system32\da-DK
2009-01-17 18:11:56 ----D---- C:\Windows\system32\com
2009-01-17 18:11:52 ----D---- C:\Windows\system32\it-IT
2009-01-17 18:11:52 ----D---- C:\Windows\system32\el-GR
2009-01-17 18:11:51 ----D---- C:\Windows\system32\sysprep
2009-01-17 18:11:51 ----D---- C:\Windows\system32\oobe
2009-01-17 18:11:51 ----D---- C:\Windows\system32\migration
2009-01-17 18:11:50 ----D---- C:\Windows\system32\sv-SE
2009-01-17 18:11:50 ----D---- C:\Windows\system32\SLUI
2009-01-17 18:11:50 ----D---- C:\Windows\system32\setup
2009-01-17 18:11:50 ----D---- C:\Windows\system32\ru-RU
2009-01-17 18:11:50 ----D---- C:\Windows\system32\pt-PT
2009-01-17 18:11:50 ----D---- C:\Windows\system32\ias
2009-01-17 18:11:50 ----D---- C:\Windows\system32\hu-HU
2009-01-17 18:11:50 ----D---- C:\Windows\system32\he-IL
2009-01-17 18:11:50 ----D---- C:\Windows\system32\fr-FR
2009-01-17 18:11:50 ----D---- C:\Windows\system32\fi-FI
2009-01-17 18:11:50 ----D---- C:\Windows\system32\cs-CZ
2009-01-17 18:11:50 ----D---- C:\Windows\system32\AdvancedInstallers
2009-01-17 18:11:49 ----D---- C:\Windows\system32\zh-TW
2009-01-17 18:11:49 ----D---- C:\Windows\system32\zh-CN
2009-01-17 18:11:49 ----D---- C:\Windows\system32\ro-RO
2009-01-17 18:11:49 ----D---- C:\Windows\system32\pl-PL
2009-01-17 18:11:49 ----D---- C:\Windows\system32\manifeststore
2009-01-17 18:11:49 ----D---- C:\Windows\system32\ja-JP
2009-01-17 18:11:49 ----D---- C:\Windows\system32\es-ES
2009-01-17 18:11:48 ----D---- C:\Windows\system32\drivers
2009-01-17 18:11:45 ----D---- C:\Windows\system32\wbem
2009-01-17 18:11:45 ----D---- C:\Windows\system32\tr-TR
2009-01-17 18:11:44 ----D---- C:\Windows\system32\nl-NL
2009-01-17 18:11:44 ----D---- C:\Windows\system32\nb-NO
2009-01-17 18:11:44 ----D---- C:\Windows\system32\ar-SA
2009-01-17 18:11:43 ----D---- C:\Windows\system32\migwiz
2009-01-17 18:11:42 ----D---- C:\Windows\system32\pt-BR
2009-01-17 18:11:17 ----RSD---- C:\Windows\Fonts
2009-01-17 18:11:17 ----D---- C:\Windows\AppPatch
2009-01-17 18:11:10 ----D---- C:\Windows\Boot
2009-01-17 18:11:09 ----D---- C:\Windows\system32\Boot
2009-01-17 17:59:58 ----A---- C:\Windows\system32\ifxcardm.dll
2009-01-17 17:59:56 ----A---- C:\Windows\system32\axaltocm.dll
2009-01-17 17:49:01 ----RD---- C:\Program Files
2009-01-17 11:20:43 ----HD---- C:\ProgramData
2009-01-16 16:35:41 ----D---- C:\Program Files\Mozilla Firefox
2009-01-16 16:35:40 ----D---- C:\Users\Imperatore\AppData\Roaming\Mozilla
2009-01-13 21:00:55 ----D---- C:\Users\Imperatore\AppData\Roaming\Azureus
2009-01-13 20:08:06 ----D---- C:\Program Files\Mozilla Thunderbird
2009-01-11 19:11:36 ----SD---- C:\Users\Imperatore\AppData\Roaming\Microsoft
2009-01-11 19:09:13 ----HD---- C:\Program Files\InstallShield Installation Information
2009-01-11 19:07:39 ----SD---- C:\Windows\Downloaded Program Files
2009-01-11 12:33:59 ----D---- C:\Program Files\Common Files
2009-01-11 12:04:27 ----D---- C:\Windows\system32\Tasks
2009-01-10 19:02:00 ----D---- C:\Program Files\Winamp
2009-01-10 18:59:12 ----DC---- C:\Windows\system32\DRVSTORE
2009-01-10 09:21:47 ----D---- C:\Program Files\WinRAR
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2008-07-21 24392]
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2006-11-15 32256]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2006-11-15 43520]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2006-11-15 37376]
R3 athrusb;Atheros Wireless LAN USB device driver; C:\Windows\system32\DRIVERS\athrusb.sys [2007-01-08 449024]
R3 CmBatt;Treiber für Microsoft-ACPI-Kontrollmethodenkompatible Batterie; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-19 14208]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 2302976]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2006-11-23 1652968]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2006-12-20 67072]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-19 88576]
R3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2006-10-09 981504]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2006-11-22 179896]
R3 VClone;VClone; C:\Windows\system32\DRIVERS\VClone.sys [2008-09-24 29184]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-19 11264]
R3 X10Hid;X10 Hid Device; C:\Windows\System32\Drivers\x10hid.sys [2006-11-17 13976]
R3 XUIF;X10 USB Wireless Transceiver; C:\Windows\System32\Drivers\x10ufx2.sys [2006-11-30 27416]
S1 Ndisprot.sys;Ndisprot.sys; C:\Windows\system32\drivers\Ndisprot.sys [2008-12-05 29184]
S3 drmkaud;Microsoft Kernel-DRM-Audioentschlüsselung; C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
S3 FETNDIS;VIA Rhine-Familie--Fast-Ethernet-Adaptertreiberdienst; C:\Windows\system32\DRIVERS\fetnd5.sys [2006-11-02 45568]
S3 HdAudAddService;Microsoft 1.1 UAA-Funktionstreiber für High Definition Audio-Dienst; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 ialm;ialm; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 2302976]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\mbamswissarmy.sys [2009-01-14 38496]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Microsoft Proxy für Streaming Clock; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
S3 MSPQM;Microsoft Proxy für Streaming Quality Manager; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink-Konvertierung; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
S3 PhilCap;PhilCap service; C:\Windows\system32\DRIVERS\PhilCap.sys [2006-10-12 1053824]
S3 R300;R300; C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-02 2028032]
S3 s117bus;Sony Ericsson Device 117 driver (WDM); C:\Windows\system32\DRIVERS\s117bus.sys [2007-06-25 82984]
S3 s117mdfl;Sony Ericsson Device 117 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s117mdfl.sys [2007-06-25 14888]
S3 s117mdm;Sony Ericsson Device 117 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s117mdm.sys [2007-06-25 108456]
S3 s117mgmt;Sony Ericsson Device 117 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s117mgmt.sys [2007-06-25 100264]
S3 s117nd5;Sony Ericsson Device 117 USB Ethernet Emulation SEMC117 (NDIS); C:\Windows\system32\DRIVERS\s117nd5.sys [2007-06-25 22952]
S3 s117obex;Sony Ericsson Device 117 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s117obex.sys [2007-06-25 98344]
S3 s117unic;Sony Ericsson Device 117 USB Ethernet Emulation SEMC117 (WDM); C:\Windows\system32\DRIVERS\s117unic.sys [2007-06-25 98856]
S3 SANDRA;SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2009\WNt500x86\Sandra.sys []
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-01-19 39936]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 a2AntiMalware;a-squared Anti-Malware Service; C:\Program Files\a-squared Anti-Malware\a2service.exe [2008-10-04 418936]
R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-09-10 611664]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2006-10-19 61440]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [2001-02-23 270336]
R2 x10nets;X10 Device Network Service; C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe [2001-11-12 20480]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance; C:\Program Files\ALDI Foto Service Nord\Common\Database\bin\fbserver.exe []
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S4 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2006-12-05 774144]
S4 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2006-12-23 262144]
-----------------EOF-----------------