PDA

View Full Version : Virtumonde Removal - Nr. X



oWn4g3
2008-04-16, 09:40
Hi, I'm the next in line I guess... :sad:
I know its a lot of work but it would be very nice if someone helped me :cleaning:

I have to start with a Spybot Log and a HJT Log right?

oWn4g3
2008-04-16, 09:58
I have renamed the HJT exe to own4g3.exe and made a scan and log


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:57:38, on 16.04.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\Creative\Shared Files\CTAudSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\Java\jre1.6.0_05\bin\jusched.exe
C:\Programme\Gemeinsame Dateien\Logitech\LCD Manager\lcdmon.exe
C:\Programme\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
C:\Programme\Creative\Shared Files\Module Loader\DLLML.exe
C:\Programme\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programme\Gemeinsame Dateien\Logitech\LCD Manager\Applets\LCDClock.exe
C:\Programme\Gemeinsame Dateien\Logitech\LCD Manager\Applets\LCDMedia.exe
C:\Programme\DAEMON Tools Pro\DTProAgent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\Bonjour\mDNSResponder.exe
C:\Programme\Logitech\SetPoint\SetPoint.exe
C:\Programme\ESET\ESET Smart Security\ekrn.exe
C:\Programme\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\LxrSII1s.exe
C:\Programme\CDBurnerXP\NMSAccessU.exe
C:\Programme\Gemeinsame Dateien\Logitech\KhalShared\KHALMNPR.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Programme\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programme\Mozilla Firefox\firefox.exe
C:\Programme\Spybot - Search & Destroy\SpybotSD.exe
C:\Programme\Trend Micro\HijackThis\oWn4g3.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: {3d7fc2ea-8182-03f8-f2a4-5fd23b833a25} - {52a338b3-2df5-4a2f-8f30-2818ae2cf7d3} - C:\WINDOWS\system32\mbxtviru.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {83545753-2A0F-438E-AB2F-6679BE9D1FBE} - C:\WINDOWS\system32\efcBrRLf.dll
O2 - BHO: (no name) - {8D5A848F-AF4F-4588-BE54-3741AFDFCE55} - (no file)
O2 - BHO: (no name) - {AB8A2536-8D9B-44F4-BE95-06F7B4610445} - C:\WINDOWS\system32\ddcCVPif.dll
O2 - BHO: (no name) - {BA7CB974-956C-456A-BB82-BEEC3B5E1750} - C:\WINDOWS\system32\urqOHWPG.dll (file missing)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Programme\Gemeinsame Dateien\Logitech\LCD Manager\lcdmon.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [VolPanel] "C:\Programme\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Programme\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Programme\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [egui] "C:\Programme\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [1c42bc13] rundll32.exe "C:\WINDOWS\system32\cmhoajpt.dll",b
O4 - HKLM\..\Run: [ati2sgav] "C:\WINDOWS\system32\ati2sgav.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NBKeyScan] "C:\Programme\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [BM1f718f8f] Rundll32.exe "C:\WINDOWS\system32\iaecjrpf.dll",s
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Programme\DAEMON Tools Pro\DTProAgent.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Programme\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Programme\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Programme\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Programme\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Programme\Free Download Manager\dllink.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V02002/ocx/15030/CTPID.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: efcBrRLf - C:\WINDOWS\SYSTEM32\efcBrRLf.dll
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Programme\Bonjour\mDNSResponder.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Programme\Creative\Shared Files\CTAudSvc.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Programme\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Programme\ESET\ESET Smart Security\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programme\Gemeinsame Dateien\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Lexar Secure II (LxrSII1s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrSII1s.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Programme\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Programme\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: TuneUp Drive Defrag-Dienst (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

--
End of file - 8098 bytes

oWn4g3
2008-04-16, 10:01
Kaspersky Online Scan doesnt work. I click Accept but nothing happens... I can't even enter google anymore...

oWn4g3
2008-04-16, 12:10
Ok, got kaspersky Online running for 1:33 hours :lip:
LOG:


-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Wednesday, April 16, 2008 12:07:09 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 16/04/2008
Kaspersky Anti-Virus database records: 709546
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
F:\
H:\
I:\

Scan Statistics:
Total number of scanned objects: 322315
Number of viruses found: 5
Number of infected objects: 10
Number of suspicious objects: 0
Duration of the scan process: 01:33:30

Infected Object Name / Virus Name / Last Action
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ESET\ESET Smart Security\Charon\CACHE.NDB Object is locked skipped
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ESET\ESET Smart Security\Logs\epfwlog.dat Object is locked skipped
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ESET\ESET Smart Security\Logs\virlog.dat Object is locked skipped
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ESET\ESET Smart Security\Logs\warnlog.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Cookies\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Verlauf\History.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\NTUSER.DAT Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\NTUSER.DAT Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Mozilla\Firefox\Profiles\lkn2udva.default\cert8.db Object is locked skipped
C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Mozilla\Firefox\Profiles\lkn2udva.default\flashgot.log Object is locked skipped
C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Mozilla\Firefox\Profiles\lkn2udva.default\history.dat Object is locked skipped
C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Mozilla\Firefox\Profiles\lkn2udva.default\key3.db Object is locked skipped
C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Mozilla\Firefox\Profiles\lkn2udva.default\search.sqlite Object is locked skipped
C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Mozilla\Firefox\Profiles\lkn2udva.default\urlclassifier2.sqlite Object is locked skipped
C:\Dokumente und Einstellungen\oWn4g3\Cookies\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Anwendungsdaten\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Anwendungsdaten\Mozilla\Firefox\Profiles\lkn2udva.default\Cache\_CACHE_001_ Object is locked skipped
C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Anwendungsdaten\Mozilla\Firefox\Profiles\lkn2udva.default\Cache\_CACHE_002_ Object is locked skipped
C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Anwendungsdaten\Mozilla\Firefox\Profiles\lkn2udva.default\Cache\_CACHE_003_ Object is locked skipped
C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Anwendungsdaten\Mozilla\Firefox\Profiles\lkn2udva.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Temporary Internet Files\Content.IE5\79GE3VAV\idkfa[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.okj skipped
C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Temporary Internet Files\Content.IE5\XJT5D1R2\idkfa[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.okj skipped
C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Verlauf\History.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Verlauf\History.IE5\MSHist012008041620080417\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\oWn4g3\NTUSER.DAT Object is locked skipped
C:\Dokumente und Einstellungen\oWn4g3\ntuser.dat.LOG Object is locked skipped
C:\Programme\Alcohol Soft\Alcohol 120\StarWind\logs\sw_ae-20080416-091810.log Object is locked skipped
C:\Programme\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.631 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\WINDOWS\CSC\00000001 Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\S96B3E77A.tmp Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\iaecjrpf.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.okj skipped
C:\WINDOWS\system32\pbsvc.exe Infected: not-a-virus:AdWare.Win32.AdMedia.br skipped
C:\WINDOWS\system32\vfkwwqpo.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.okj skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
E:\Software & Tools\mirc616.exe/data0001.bin Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
E:\Software & Tools\mirc616.exe mIRC: infected - 1 skipped
E:\Software & Tools\Nero 8 Ultra Edition 8.2.8.0\Nero-8.2.8.0_eng_trial.exe/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
E:\Software & Tools\Nero 8 Ultra Edition 8.2.8.0\Nero-8.2.8.0_eng_trial.exe 7-Zip: infected - 1 skipped

Scan process completed.


Hope that these things will help. Virtumonde is quite annoying...

oWn4g3
2008-04-18, 10:40
I thought that I might have been forgotten so I decided to do a ComboFix Scan.
Here is the log:


ComboFix 08-04-16.5 - oWn4g3 2008-04-18 10:30:33.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1031.18.1621 [GMT 2:00]
ausgeführt von:: C:\Dokumente und Einstellungen\oWn4g3\Desktop\ComboFix.exe
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

(((((((((((((((((((((((((((((((((((( Weitere L”schungen ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\bmxkmoni.ini
C:\WINDOWS\system32\Cfx32.lic
C:\WINDOWS\system32\cfx32.ocx
C:\WINDOWS\system32\ddcCVPif.dll
C:\WINDOWS\system32\efcBrRLf.dll
C:\WINDOWS\system32\fgudcdgb.dll
C:\WINDOWS\system32\fiPVCcdd.ini
C:\WINDOWS\system32\fiPVCcdd.ini2
C:\WINDOWS\system32\GPWHOqru.ini
C:\WINDOWS\system32\GPWHOqru.ini2
C:\WINDOWS\system32\hjrpanhj.dll
C:\WINDOWS\system32\hvwdodic.dll
C:\WINDOWS\system32\inomkxmb.dll
C:\WINDOWS\system32\kvmsfrtl.ini
C:\WINDOWS\system32\ltrfsmvk.dll
C:\WINDOWS\system32\mbxtviru.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\xbbeNqru.ini
C:\WINDOWS\system32\xbbeNqru.ini2

.
((((((((((((((((((((((( Dateien erstellt von 2008-03-18 bis 2008-04-18 ))))))))))))))))))))))))))))))
.

2008-04-17 22:50 . 2008-04-18 10:10 <DIR> d-------- C:\Programme\Hamachi
2008-04-17 19:15 . 2008-04-17 19:15 <DIR> d-------- C:\Programme\Pivot Stickfigure Animator
2008-04-16 14:45 . 2008-04-17 17:59 <DIR> d-------- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TrackMania
2008-04-16 10:15 . 2008-04-16 10:15 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-04-16 10:15 . 2008-04-16 10:15 <DIR> d-------- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Kaspersky Lab
2008-04-16 09:56 . 2008-04-16 09:56 <DIR> d-------- C:\Programme\Trend Micro
2008-04-16 09:26 . 2008-04-17 09:26 414 ---hs---- C:\WINDOWS\system32\tpjaohmc.ini
2008-04-15 16:30 . 2008-04-15 16:30 <DIR> d-------- C:\WINDOWS\nview
2008-04-15 16:30 . 2008-04-15 16:30 <DIR> d-------- C:\WINDOWS\nvidia icons
2008-04-15 16:30 . 2008-03-24 11:27 442,368 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2008-04-15 16:30 . 2008-03-24 19:52 442,368 --a------ C:\WINDOWS\system32\nvudisp.exe
2008-04-15 16:30 . 2008-04-18 10:36 175,605 --a------ C:\WINDOWS\system32\nvapps.xml
2008-04-15 16:30 . 2008-03-24 19:52 17,937 --a------ C:\WINDOWS\system32\nvdisp.nvu
2008-04-15 16:29 . 2008-04-15 16:29 <DIR> d-------- C:\NVIDIA
2008-04-15 14:56 . 2008-04-15 21:09 594 ---hs---- C:\WINDOWS\system32\hsaodgyr.ini
2008-04-15 14:47 . 2008-04-15 14:47 272,384 --------- C:\WINDOWS\system32\urqOHWPG.dll_old
2008-04-14 19:48 . 2008-04-15 14:42 <DIR> d-------- C:\Programme\tempa
2008-04-14 19:48 . 2008-04-08 11:50 206,191 --a------ C:\WINDOWS\system32\ati2sgav.exe
2008-04-14 16:07 . 2008-04-15 20:37 559 --a------ C:\WINDOWS\wininit.ini
2008-04-14 16:03 . 2008-04-14 16:03 307,968 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
2008-04-14 16:02 . 2008-02-27 13:15 28,416 --a------ C:\WINDOWS\system32\uxtuneup.dll
2008-04-14 07:20 . 2008-04-14 16:26 354 ---hs---- C:\WINDOWS\system32\tflvpiln.ini
2008-04-14 07:12 . 2008-04-17 08:54 101,091 --a------ C:\WINDOWS\BM1f718f8f.xml
2008-04-13 14:15 . 2008-04-13 14:16 <DIR> d-------- C:\WINDOWS\Sins Bonuspack
2008-04-11 21:36 . 2008-04-13 14:49 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-11 21:36 . 2008-04-11 21:36 1,409 --a------ C:\WINDOWS\QTFont.for
2008-04-11 17:07 . 2008-04-11 17:07 <DIR> d-------- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Ubisoft
2008-04-11 16:54 . 2008-04-14 19:48 441,652 --a------ C:\WINDOWS\system32\winamp.exe
2008-04-09 14:33 . 2008-04-09 14:33 <DIR> d-------- C:\WINDOWS\.jagex_cache_32
2008-04-06 12:39 . 2000-07-08 15:06 87,040 --a------ C:\WINDOWS\UnGins.exe
2008-04-06 12:34 . 2008-04-06 12:34 457,728 --a------ C:\xdfe52.dll
2008-04-06 12:34 . 2008-04-06 12:34 69,120 --a------ C:\atm.dll
2008-04-06 12:34 . 2008-04-06 12:34 45,056 --a------ C:\UNACE.dll
2008-04-03 01:26 . 2008-04-03 01:26 41,296 --a------ C:\WINDOWS\system32\xfcodec.dll
2008-03-27 17:17 . 2008-03-27 21:21 <DIR> d-------- C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Command & Conquer 3 Kanes Rache
2008-03-27 00:04 . 2008-04-05 01:41 <DIR> d---s---- C:\Programme\HLSW
2008-03-27 00:04 . 2008-04-05 02:52 <DIR> d-------- C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\HLSW
2008-03-26 18:26 . 2008-03-26 18:26 <DIR> d-------- C:\Programme\OpenOffice.org 2.4
2008-03-25 15:38 . 2008-03-25 15:38 34,198 --a------ C:\Star Wars Battlefront II .mds
2008-03-24 16:25 . 2008-03-25 15:42 3,914,283,008 --a------ C:\Star Wars Battlefront II .mdf
2008-03-23 18:05 . 2008-03-23 18:05 122 --a------ C:\WINDOWS\WA.INI
2008-03-23 18:04 . 2008-03-23 18:04 1,559,605 --a------ C:\WINDOWS\WANEUninstaller.exe
2008-03-23 15:36 . 2008-03-23 15:36 <DIR> d-------- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Age of Empires 3
2008-03-20 18:06 . 2008-03-20 18:06 <DIR> d-------- C:\WINDOWS\PreviewSoft
2008-03-20 18:06 . 2008-03-20 18:06 <DIR> d-------- C:\WINDOWS\Noslip
2008-03-20 18:06 . 2008-03-20 18:06 <DIR> d-------- C:\Programme\Ulead GIF Animator 5
2008-03-20 18:06 . 1999-10-15 13:50 1,056,768 --a------ C:\WINDOWS\system32\ROBOEX32.DLL
2008-03-20 18:06 . 1999-01-28 16:44 49,152 --a------ C:\WINDOWS\system32\INETWH32.dll
2008-03-20 18:06 . 2008-03-20 18:06 4,808 --a------ C:\WINDOWS\system32\gaeffect.sti
2008-03-20 18:06 . 2008-03-20 18:06 3,176 --a------ C:\WINDOWS\system32\gafilter.sti
2008-03-20 18:06 . 2008-03-20 20:50 550 --ah----- C:\os466477.bin
2008-03-20 18:06 . 2008-03-20 20:50 449 --ah----- C:\WINDOWS\system32\ws344069.ocx
2008-03-20 18:06 . 2008-03-20 20:50 312 --a------ C:\WINDOWS\ULEAD32.INI
2008-03-19 16:18 . 2008-03-19 16:18 <DIR> d-------- C:\Programme\Latein-W”rterbuch
2008-03-18 18:42 . 2008-04-17 22:47 <DIR> d-------- C:\temp

.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-17 22:42 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Xfire
2008-04-17 22:41 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Hamachi
2008-04-17 20:52 16,224 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys
2008-04-17 17:17 --------- d-----w C:\Programme\Trillian
2008-04-17 17:15 --------- d-----w C:\Programme\PowerArchiver
2008-04-17 17:11 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\teamspeak2
2008-04-17 14:16 --------- d-s---w C:\Programme\Xfire
2008-04-17 14:14 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\OpenOffice.org2
2008-04-17 07:11 --------- d-----w C:\Programme\BOINC
2008-04-16 12:55 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Skype
2008-04-16 11:08 --------- d-----w C:\Programme\Gemeinsame Dateien\Wise Installation Wizard
2008-04-16 10:14 --------- d-----w C:\Programme\Mozilla Thunderbird
2008-04-16 08:13 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\uTorrent
2008-04-15 19:27 --------- d-----w C:\Programme\mIRC
2008-04-15 19:27 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\mIRC
2008-04-15 17:11 --------- d-----w C:\Programme\Gemeinsame Dateien\Nero
2008-04-14 14:03 --------- d-----w C:\Programme\TuneUp Utilities 2008
2008-04-13 12:07 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Free Download Manager
2008-04-11 15:07 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-04-11 15:07 22,328 ----a-w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\PnkBstrK.sys
2008-04-11 14:55 --------- d--h--w C:\Programme\InstallShield Installation Information
2008-04-10 16:10 --------- d-----w C:\Programme\SpeedFan
2008-03-31 16:16 --------- d-----w C:\Programme\Winamp
2008-03-31 16:16 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Winamp
2008-03-24 17:52 6,547,872 ----a-w C:\WINDOWS\system32\drivers\nv4_mini.sys
2008-03-19 14:18 --------- d-----w C:\Programme\Latein-Wörterbuch
2008-03-17 16:35 --------- d-----w C:\Programme\Java
2008-03-16 12:50 --------- d-----w C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Creative
2008-03-16 12:40 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Creative
2008-03-14 09:38 --------- d-----w C:\Programme\Audacity
2008-03-09 19:02 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Media Player Classic
2008-03-09 19:01 --------- d-----w C:\Programme\XP Codec Pack
2008-03-07 13:24 97,216 ----a-w C:\WINDOWS\system32\drivers\AnyDVD.sys
2008-03-02 19:27 --------- d---a-w C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP
2008-03-02 10:12 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\dvdcss
2008-02-29 09:21 --------- d-----w C:\Programme\AGEIA Technologies
2008-02-25 19:32 --------- d-----w C:\Programme\DivX
2008-02-25 08:45 189,464 ----a-w C:\WINDOWS\system32\drivers\haP17v2k.sys
2008-02-25 08:45 15,896 ----a-w C:\WINDOWS\system32\drivers\pfmodnt.sys
2008-02-25 08:44 92,696 ----a-w C:\WINDOWS\system32\drivers\emupia2k.sys
2008-02-25 08:44 797,720 ----a-w C:\WINDOWS\system32\drivers\ha10kx2k.sys
2008-02-25 08:44 162,840 ----a-w C:\WINDOWS\system32\drivers\haP16v2k.sys
2008-02-25 08:44 157,208 ----a-w C:\WINDOWS\system32\drivers\ctsfm2k.sys
2008-02-25 08:44 14,360 ----a-w C:\WINDOWS\system32\drivers\ctprxy2k.sys
2008-02-25 08:44 1,172,504 ----a-w C:\WINDOWS\system32\drivers\ha20x2k.sys
2008-02-25 08:43 524,312 ----a-w C:\WINDOWS\system32\drivers\ctaud2k.sys
2008-02-25 08:43 511,000 ----a-w C:\WINDOWS\system32\drivers\ctac32k.sys
2008-02-25 08:43 346,856 ----a-w C:\WINDOWS\system32\drivers\ctdvda2k.sys
2008-02-25 08:43 18,840 ----a-w C:\WINDOWS\system32\drivers\CTGAME.SYS
2008-02-25 08:43 127,000 ----a-w C:\WINDOWS\system32\drivers\ctoss2k.sys
2008-02-25 08:43 1,372,568 ----a-w C:\WINDOWS\system32\drivers\CTMMFILT.SYS
2008-02-25 08:43 1,366,424 ----a-w C:\WINDOWS\system32\drivers\CT0531FL.SYS
2008-02-20 18:52 --------- d-----w C:\Programme\Unity
2008-02-18 18:05 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\ESET
2008-02-18 18:03 --------- d-----w C:\Programme\Eset
2008-02-18 18:03 --------- d-----w C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ESET
2008-02-18 17:30 --------- d-----w C:\Programme\Xvid
2008-02-18 17:28 --------- d-----w C:\Programme\FreshUI
.

(((((((((((((((((((((((((((( Autostart Punkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Hinweis* leere Eintrage & legitime Standardeintrage werden nicht angezeigt.

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BA7CB974-956C-456A-BB82-BEEC3B5E1750}]
C:\WINDOWS\system32\urqOHWPG.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Pro Agent"="C:\Programme\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 15:08 136136]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:57 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Programme\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"Launch LCDMon"="C:\Programme\Gemeinsame Dateien\Logitech\LCD Manager\lcdmon.exe" [2007-04-26 17:54 774168]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 16:32 56080 C:\WINDOWS\KHALMNPR.Exe]
"VolPanel"="C:\Programme\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" [2006-07-13 15:11 122880]
"AudioDrvEmulator"="C:\Programme\Creative\Shared Files\Module Loader\DLLML.exe" [2005-11-04 19:07 49152]
"egui"="C:\Programme\ESET\ESET Smart Security\egui.exe" [2007-12-21 09:21 1443072]
"CTHelper"="CTHELPER.EXE" [2008-02-20 21:58 19456 C:\WINDOWS\system32\CtHelper.exe]
"ati2sgav"="C:\WINDOWS\system32\ati2sgav.exe" [2008-04-08 11:50 206191]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-03-24 19:52 13524992]
"nwiz"="nwiz.exe" [2008-03-24 19:52 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-03-24 19:52 86016]
"NBKeyScan"="C:\Programme\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [ ]
"BM1f718f8f"="C:\WINDOWS\system32\iaecjrpf.dll" [ ]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcBrRLf]
efcBrRLf.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
--a------ 2008-03-07 15:26 89024 C:\Programme\SlySoft\AnyDVD\AnyDVD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeviceDiscovery]
--a------ 2003-05-21 19:37 229437 C:\Programme\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2003-06-25 12:24 49152 C:\Programme\Hewlett-Packard\HP Software Update\HPWuSchd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
--a------ 2003-06-26 14:17 188416 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
--a------ 2007-05-11 02:08 2512392 C:\WINDOWS\system32\oodtray.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"AlcoholAutomount"="C:\Programme\Alcohol Soft\Alcohol 120\axcmd.exe" /automount

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="C:\Programme\QuickTime\qttask.exe" -atboottime
"UpdReg"=C:\WINDOWS\UpdReg.EXE
"NeroFilterCheck"=C:\Programme\Gemeinsame Dateien\Nero\Lib\NeroCheck.exe
"Adobe Reader Speed Launcher"="C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"CTxfiHlp"=CTXFIHLP.EXE

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programme\\Bonjour\\mDNSResponder.exe"=
"C:\\Programme\\uTorrent\\uTorrent.exe"=
"D:\\Pro Evolution Soccer 2008\\PES2008.exe"=
"C:\\Programme\\ICQLite\\ICQLite.exe"=

R2 CTAudSvcService;Creative Audio Service;C:\Programme\Creative\Shared Files\CTAudSvc.exe [2008-03-07 20:24]
R2 LxrSII1d;Secure II Driver;C:\WINDOWS\system32\Drivers\LxrSII1d.sys [2006-12-14 10:37]
R2 NMSAccessU;NMSAccessU;C:\Programme\CDBurnerXP\NMSAccessU.exe [2007-10-12 09:34]
R2 UxTuneUp;TuneUp Designerweiterung;C:\WINDOWS\System32\svchost.exe [2004-08-04 00:58]
R3 ha20x2k;Creative 20X HAL Driver;C:\WINDOWS\system32\drivers\ha20x2k.sys [2008-02-25 10:44]
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;C:\WINDOWS\system32\DRIVERS\RTL8187.sys [2006-06-16 09:30]
S3 TuneUp.Defrag;TuneUp Drive Defrag-Dienst;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-04-14 16:03]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{25584aea-0633-11dd-9107-0018f3645f89}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL DVR/AutoRun.exe start.exe


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B9482BB3-D290-B4EC-C404-A72331581690}]
C:\WINDOWS\system32\winamp.exe
.
Inhalt des "geplante Tasks" Ordners
"2008-04-18 08:36:38 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Programme\TuneUp Utilities 2008\OneClickStarter.exe
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-18 10:36:54
Windows 5.1.2600 Service Pack 2 NTFS

Scanne versteckte Prozesse...

Scanne versteckte Autostart Eintr„ge...

Scanne versteckte Dateien...


C:\WINDOWS\TEMP\u5jg9yoj.TMP

Scan erfolgreich abgeschlossen
versteckte Dateien: 1

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Programme\Bonjour\mDNSResponder.exe
C:\Programme\Eset\ESET Smart Security\ekrn.exe
C:\WINDOWS\system32\LxrSII1s.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Programme\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\CTxfispi.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programme\Gemeinsame Dateien\Logitech\LCD Manager\Applets\LCDClock.exe
C:\Programme\Gemeinsame Dateien\Logitech\LCD Manager\Applets\LCDMedia.exe
C:\Programme\Logitech\SetPoint\SetPoint.exe
C:\Programme\Internet Explorer\iexplore.exe
C:\Programme\Gemeinsame Dateien\Logitech\KhalShared\KHALMNPR.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2008-04-18 10:38:47 - machine was rebooted [oWn4g3]
ComboFix-quarantined-files.txt 2008-04-18 08:38:38

10 Verzeichnis(se), 5,669,212,160 Bytes frei
12 Verzeichnis(se), 5,613,842,432 Bytes frei


Hope that it was the right decision and I hope that you can help me.
Thanks in advance :)

Blade81
2008-04-19, 17:52
Hi

Upload following files to http://virusscan.jotti.org and post back the results:
C:\WINDOWS\UnGins.exe
C:\xdfe52.dll
C:\atm.dll
C:\UNACE.dll



Open notepad and copy/paste the text in the quotebox below into it:



File::
C:\WINDOWS\system32\tpjaohmc.ini
C:\WINDOWS\system32\hsaodgyr.ini
C:\WINDOWS\system32\urqOHWPG.dll_old
C:\WINDOWS\system32\tflvpiln.ini
C:\WINDOWS\BM1f718f8f.xml
C:\WINDOWS\UnGins.exe
C:\WINDOWS\system32\winamp.exe

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BA7CB974-956C-456A-BB82-BEEC3B5E1750}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BM1f718f8f"=-

[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcBrRLf]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{25584aea-0633-11dd-9107-0018f3645f89}]

[-HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B9482BB3-D290-B4EC-C404-A72331581690}]



Save this as
CFScript


http://users.pandora.be/bluepatchy/miekiemoes/images/CFScript.gif

Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.


Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.


Download ATF (Atribune Temp File) Cleaner© by Atribune (http://www.atribune.org/ccount/click.php?id=1) to your desktop.

Double-click ATF Cleaner.exe to open it

Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache
*The other boxes are optional*
Then click the Empty Selected button.

If you use Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

If you use Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Click Exit on the Main menu to close the program.


Run Kaspersky online scanner and post back its report & a fresh hjt log (without forgetting ComboFix resultant log meantioned above).

oWn4g3
2008-04-19, 23:33
Thanks for your help, I guess there is light at the end of the tunnel :D

File: UnGins.exe
Status: OK
MD5: d6669c265d4280b3f149fae882d634a5
Packers detected: -
Bit9 reports: No threat detected (more info)

--------------
File: xdfe52.dll
Status: INFECTED/MALWARE
MD5: 89b5b81046a34f27aefd9e827c669d46
Packers detected: -
Bit9 reports: High threat detected (more info)

ClamAV Found Trojan.Packed-4
Sophos Antivirus Found Mal/Packer

--------------

File: atm.dll
Status: OK
MD5: 142aea530128844fef12d8c9ff1a491c
Packers detected: -
Bit9 reports: No threat detected (more info)

--------------

File: UNACE.dll
Status: OK
MD5: c7fc09f6c3650331619f553538e3a7c3
Packers detected: PE_PATCH
Bit9 reports: No threat detected (more info)


I will now start Combofix with CFScript.txt

oWn4g3
2008-04-19, 23:38
ComboFix 08-04-16.5 - oWn4g3 2008-04-19 23:35:08.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1031.18.1523 [GMT 2:00]
ausgeführt von:: C:\Dokumente und Einstellungen\oWn4g3\Desktop\ComboFix.exe
Command switches used :: C:\Dokumente und Einstellungen\oWn4g3\Desktop\CFScript.txt
* Neuer Wiederherstellungspunkt wurde erstellt
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((( Dateien erstellt von 2008-03-19 bis 2008-04-19 ))))))))))))))))))))))))))))))
.

2008-04-17 22:50 . 2008-04-18 10:10 <DIR> d-------- C:\Programme\Hamachi
2008-04-17 19:15 . 2008-04-17 19:15 <DIR> d-------- C:\Programme\Pivot Stickfigure Animator
2008-04-16 14:45 . 2008-04-19 23:03 <DIR> d-------- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TrackMania
2008-04-16 10:15 . 2008-04-16 10:15 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-04-16 10:15 . 2008-04-16 10:15 <DIR> d-------- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Kaspersky Lab
2008-04-16 09:56 . 2008-04-16 09:56 <DIR> d-------- C:\Programme\Trend Micro
2008-04-16 09:26 . 2008-04-17 09:26 414 ---hs---- C:\WINDOWS\system32\tpjaohmc.ini
2008-04-15 16:30 . 2008-04-15 16:30 <DIR> d-------- C:\WINDOWS\nview
2008-04-15 16:30 . 2008-04-15 16:30 <DIR> d-------- C:\WINDOWS\nvidia icons
2008-04-15 16:30 . 2008-03-24 11:27 442,368 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2008-04-15 16:30 . 2008-03-24 19:52 442,368 --a------ C:\WINDOWS\system32\nvudisp.exe
2008-04-15 16:30 . 2008-04-19 22:57 175,605 --a------ C:\WINDOWS\system32\nvapps.xml
2008-04-15 16:30 . 2008-03-24 19:52 17,937 --a------ C:\WINDOWS\system32\nvdisp.nvu
2008-04-15 16:29 . 2008-04-15 16:29 <DIR> d-------- C:\NVIDIA
2008-04-15 14:56 . 2008-04-15 21:09 594 ---hs---- C:\WINDOWS\system32\hsaodgyr.ini
2008-04-15 14:47 . 2008-04-15 14:47 272,384 --------- C:\WINDOWS\system32\urqOHWPG.dll_old
2008-04-14 19:48 . 2008-04-15 14:42 <DIR> d-------- C:\Programme\tempa
2008-04-14 19:48 . 2008-04-08 11:50 206,191 --a------ C:\WINDOWS\system32\ati2sgav.exe
2008-04-14 16:07 . 2008-04-15 20:37 559 --a------ C:\WINDOWS\wininit.ini
2008-04-14 16:03 . 2008-04-14 16:03 307,968 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
2008-04-14 16:02 . 2008-02-27 13:15 28,416 --a------ C:\WINDOWS\system32\uxtuneup.dll
2008-04-14 07:20 . 2008-04-14 16:26 354 ---hs---- C:\WINDOWS\system32\tflvpiln.ini
2008-04-14 07:12 . 2008-04-17 08:54 101,091 --a------ C:\WINDOWS\BM1f718f8f.xml
2008-04-13 14:15 . 2008-04-13 14:16 <DIR> d-------- C:\WINDOWS\Sins Bonuspack
2008-04-11 21:36 . 2008-04-13 14:49 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-11 21:36 . 2008-04-11 21:36 1,409 --a------ C:\WINDOWS\QTFont.for
2008-04-11 17:07 . 2008-04-11 17:07 <DIR> d-------- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Ubisoft
2008-04-11 16:54 . 2008-04-14 19:48 441,652 --a------ C:\WINDOWS\system32\winamp.exe
2008-04-09 14:33 . 2008-04-09 14:33 <DIR> d-------- C:\WINDOWS\.jagex_cache_32
2008-04-06 12:39 . 2000-07-08 15:06 87,040 --a------ C:\WINDOWS\UnGins.exe
2008-04-06 12:34 . 2008-04-06 12:34 457,728 --a------ C:\xdfe52.dll
2008-04-06 12:34 . 2008-04-06 12:34 69,120 --a------ C:\atm.dll
2008-04-06 12:34 . 2008-04-06 12:34 45,056 --a------ C:\UNACE.dll
2008-04-03 01:26 . 2008-04-03 01:26 41,296 --a------ C:\WINDOWS\system32\xfcodec.dll
2008-03-27 17:17 . 2008-03-27 21:21 <DIR> d-------- C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Command & Conquer 3 Kanes Rache
2008-03-27 00:04 . 2008-04-05 01:41 <DIR> d---s---- C:\Programme\HLSW
2008-03-27 00:04 . 2008-04-05 02:52 <DIR> d-------- C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\HLSW
2008-03-26 18:26 . 2008-03-26 18:26 <DIR> d-------- C:\Programme\OpenOffice.org 2.4
2008-03-25 15:38 . 2008-03-25 15:38 34,198 --a------ C:\Star Wars Battlefront II .mds
2008-03-24 16:25 . 2008-03-25 15:42 3,914,283,008 --a------ C:\Star Wars Battlefront II .mdf
2008-03-23 18:05 . 2008-03-23 18:05 122 --a------ C:\WINDOWS\WA.INI
2008-03-23 18:04 . 2008-03-23 18:04 1,559,605 --a------ C:\WINDOWS\WANEUninstaller.exe
2008-03-23 15:36 . 2008-03-23 15:36 <DIR> d-------- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Age of Empires 3
2008-03-20 18:06 . 2008-03-20 18:06 <DIR> d-------- C:\WINDOWS\PreviewSoft
2008-03-20 18:06 . 2008-03-20 18:06 <DIR> d-------- C:\WINDOWS\Noslip
2008-03-20 18:06 . 2008-03-20 18:06 <DIR> d-------- C:\Programme\Ulead GIF Animator 5
2008-03-20 18:06 . 1999-10-15 13:50 1,056,768 --a------ C:\WINDOWS\system32\ROBOEX32.DLL
2008-03-20 18:06 . 1999-01-28 16:44 49,152 --a------ C:\WINDOWS\system32\INETWH32.dll
2008-03-20 18:06 . 2008-03-20 18:06 4,808 --a------ C:\WINDOWS\system32\gaeffect.sti
2008-03-20 18:06 . 2008-03-20 18:06 3,176 --a------ C:\WINDOWS\system32\gafilter.sti
2008-03-20 18:06 . 2008-03-20 20:50 550 --ah----- C:\os466477.bin
2008-03-20 18:06 . 2008-03-20 20:50 449 --ah----- C:\WINDOWS\system32\ws344069.ocx
2008-03-20 18:06 . 2008-03-20 20:50 312 --a------ C:\WINDOWS\ULEAD32.INI
2008-03-19 16:18 . 2008-03-19 16:18 <DIR> d-------- C:\Programme\Latein-Wörterbuch

.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-19 16:01 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Xfire
2008-04-19 14:44 --------- d-----w C:\Programme\BOINC
2008-04-19 14:10 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\teamspeak2
2008-04-19 10:44 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\OpenOffice.org2
2008-04-19 10:18 --------- d-----w C:\Programme\Mozilla Thunderbird
2008-04-19 09:31 --------- d-s---w C:\Programme\Xfire
2008-04-18 14:14 --------- d-----w C:\Programme\PowerArchiver
2008-04-17 22:41 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Hamachi
2008-04-17 20:52 16,224 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys
2008-04-17 17:17 --------- d-----w C:\Programme\Trillian
2008-04-17 07:42 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-04-16 12:55 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Skype
2008-04-16 11:08 --------- d-----w C:\Programme\Gemeinsame Dateien\Wise Installation Wizard
2008-04-16 08:13 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\uTorrent
2008-04-15 19:27 --------- d-----w C:\Programme\mIRC
2008-04-15 19:27 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\mIRC
2008-04-15 17:11 --------- d-----w C:\Programme\Gemeinsame Dateien\Nero
2008-04-14 14:03 --------- d-----w C:\Programme\TuneUp Utilities 2008
2008-04-13 12:07 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Free Download Manager
2008-04-11 15:07 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-04-11 15:07 22,328 ----a-w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\PnkBstrK.sys
2008-04-11 15:06 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-04-11 15:03 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
2008-04-11 15:03 2,337,865 ----a-w C:\WINDOWS\system32\pbsvc.exe
2008-04-11 14:55 --------- d--h--w C:\Programme\InstallShield Installation Information
2008-04-10 16:10 --------- d-----w C:\Programme\SpeedFan
2008-03-31 16:16 --------- d-----w C:\Programme\Winamp
2008-03-31 16:16 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Winamp
2008-03-17 16:35 --------- d-----w C:\Programme\Java
2008-03-16 12:50 --------- d-----w C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Creative
2008-03-16 12:41 413,696 ----a-w C:\WINDOWS\system32\wrap_oal.dll
2008-03-16 12:41 110,592 ----a-w C:\WINDOWS\system32\OpenAL32.dll
2008-03-16 12:40 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Creative
2008-03-14 09:38 --------- d-----w C:\Programme\Audacity
2008-03-09 19:02 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Media Player Classic
2008-03-09 19:01 --------- d-----w C:\Programme\XP Codec Pack
2008-03-07 13:24 97,216 ----a-w C:\WINDOWS\system32\drivers\AnyDVD.sys
2008-03-06 15:29 962,560 ----a-w C:\WINDOWS\system32\VSFilter.dll
2008-03-04 17:12 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
2008-03-02 19:27 --------- d---a-w C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP
2008-03-02 10:12 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\dvdcss
2008-02-29 09:21 --------- d-----w C:\Programme\AGEIA Technologies
2008-02-25 19:32 --------- d-----w C:\Programme\DivX
2008-02-25 08:45 189,464 ----a-w C:\WINDOWS\system32\drivers\haP17v2k.sys
2008-02-25 08:45 15,896 ----a-w C:\WINDOWS\system32\drivers\pfmodnt.sys
2008-02-25 08:44 92,696 ----a-w C:\WINDOWS\system32\drivers\emupia2k.sys
2008-02-25 08:44 797,720 ----a-w C:\WINDOWS\system32\drivers\ha10kx2k.sys
2008-02-25 08:44 162,840 ----a-w C:\WINDOWS\system32\drivers\haP16v2k.sys
2008-02-25 08:44 157,208 ----a-w C:\WINDOWS\system32\drivers\ctsfm2k.sys
2008-02-25 08:44 14,360 ----a-w C:\WINDOWS\system32\drivers\ctprxy2k.sys
2008-02-25 08:44 1,172,504 ----a-w C:\WINDOWS\system32\drivers\ha20x2k.sys
2008-02-25 08:43 524,312 ----a-w C:\WINDOWS\system32\drivers\ctaud2k.sys
2008-02-25 08:43 511,000 ----a-w C:\WINDOWS\system32\drivers\ctac32k.sys
2008-02-25 08:43 346,856 ----a-w C:\WINDOWS\system32\drivers\ctdvda2k.sys
2008-02-25 08:43 18,840 ----a-w C:\WINDOWS\system32\drivers\CTGAME.SYS
2008-02-25 08:43 127,000 ----a-w C:\WINDOWS\system32\drivers\ctoss2k.sys
2008-02-25 08:43 1,372,568 ----a-w C:\WINDOWS\system32\drivers\CTMMFILT.SYS
2008-02-25 08:43 1,366,424 ----a-w C:\WINDOWS\system32\drivers\CT0531FL.SYS
2008-02-25 08:41 72,728 ----a-w C:\WINDOWS\system32\CTHWIUT.DLL
2008-02-25 08:41 566,296 ----a-w C:\WINDOWS\system32\CTSBLFX.DLL
2008-02-25 08:41 329,240 ----a-w C:\WINDOWS\system32\CTEDSPSY.DLL
2008-02-25 08:41 286,232 ----a-w C:\WINDOWS\system32\CTEDSPFX.DLL
2008-02-25 08:41 174,104 ----a-w C:\WINDOWS\system32\CTEAPSFX.DLL
2008-02-25 08:41 170,520 ----a-w C:\WINDOWS\system32\CT20XUT.DLL
2008-02-25 08:41 134,680 ----a-w C:\WINDOWS\system32\CTEDSPIO.DLL
2008-02-25 08:41 100,888 ----a-w C:\WINDOWS\system32\CTERFXFX.DLL
2008-02-25 08:41 1,323,544 ----a-w C:\WINDOWS\system32\CTEXFIFX.DLL
2008-02-25 08:40 98,328 ----a-w C:\WINDOWS\system32\COMMONFX.DLL
2008-02-25 08:40 551,960 ----a-w C:\WINDOWS\system32\CTAUDFX.DLL
2008-02-21 02:05 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-02-21 02:05 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-02-21 02:05 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-02-21 02:05 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-02-21 02:04 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-02-21 02:04 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2008-02-21 02:04 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-02-21 02:04 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2008-02-21 02:04 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
2008-02-21 02:04 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-02-21 02:04 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2008-02-21 02:04 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-02-21 02:04 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2008-02-21 02:04 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2008-02-21 02:04 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2008-02-21 02:04 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2008-02-21 02:03 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-02-21 02:03 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-02-20 20:00 43,520 ----a-w C:\WINDOWS\system32\CTBurst.dll
2008-02-20 19:59 86,016 ----a-w C:\WINDOWS\system32\ctcoinst.dll
2008-02-20 19:59 34,816 ----a-w C:\WINDOWS\system32\a3d.dll
2008-02-20 19:59 27,648 ----a-w C:\WINDOWS\system32\ac3api.dll
2008-02-20 19:59 163,840 ----a-w C:\WINDOWS\system32\ctdvinst.dll
2008-02-20 19:55 969,216 ----a-w C:\WINDOWS\system32\CTxfispi.exe
2008-02-20 19:55 43,520 ----a-w C:\WINDOWS\system32\Ctxfireg.exe
2008-02-20 19:55 10,752 ----a-w C:\WINDOWS\system32\Ct20xspi.dll
2008-02-20 19:49 110,080 ----a-w C:\WINDOWS\system32\ctemupia.dll
2008-02-20 19:47 49,152 ----a-w C:\WINDOWS\system32\ctdproxy.dll
2008-02-20 19:47 46,592 ----a-w C:\WINDOWS\system32\ctasio.dll
2008-02-20 19:47 174,592 ----a-w C:\WINDOWS\system32\ct_oal.dll
2008-02-20 19:47 17,920 ----a-w C:\WINDOWS\system32\ctedasio.dll
.

((((((((((((((((((((((((((((( snapshot@2008-04-18_10.38.32.46 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-18 08:34:41 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-19 20:57:27 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2008-03-30 09:24:10 70,778 ----a-w C:\WINDOWS\system32\perfc007.dat
+ 2008-04-18 08:39:15 70,778 ----a-w C:\WINDOWS\system32\perfc007.dat
- 2008-03-30 09:24:10 58,732 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-04-18 08:39:15 58,732 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-03-30 09:24:10 405,448 ----a-w C:\WINDOWS\system32\perfh007.dat
+ 2008-04-18 08:39:15 405,448 ----a-w C:\WINDOWS\system32\perfh007.dat
- 2008-03-30 09:24:10 392,432 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-04-18 08:39:15 392,432 ----a-w C:\WINDOWS\system32\perfh009.dat
.
(((((((((((((((((((((((((((( Autostart Punkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Hinweis* leere Eintrage & legitime Standardeintrage werden nicht angezeigt.

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BA7CB974-956C-456A-BB82-BEEC3B5E1750}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Pro Agent"="C:\Programme\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 15:08 136136]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:57 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Programme\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"Launch LCDMon"="C:\Programme\Gemeinsame Dateien\Logitech\LCD Manager\lcdmon.exe" [2007-04-26 17:54 774168]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 16:32 56080 C:\WINDOWS\KHALMNPR.Exe]
"VolPanel"="C:\Programme\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" [2006-07-13 15:11 122880]
"AudioDrvEmulator"="C:\Programme\Creative\Shared Files\Module Loader\DLLML.exe" [2005-11-04 19:07 49152]
"egui"="C:\Programme\ESET\ESET Smart Security\egui.exe" [2007-12-21 09:21 1443072]
"CTHelper"="CTHELPER.EXE" [2008-02-20 21:58 19456 C:\WINDOWS\system32\CtHelper.exe]
"ati2sgav"="C:\WINDOWS\system32\ati2sgav.exe" [2008-04-08 11:50 206191]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-03-24 19:52 13524992]
"nwiz"="nwiz.exe" [2008-03-24 19:52 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-03-24 19:52 86016]
"BM1f718f8f"="C:\WINDOWS\system32\iaecjrpf.dll" [ ]

C:\Dokumente und Einstellungen\All Users\Startmen\Programme\Autostart\
Logitech SetPoint.lnk - C:\Programme\Logitech\SetPoint\SetPoint.exe [2007-10-28 20:01:39 692224]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcBrRLf]
efcBrRLf.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
--a------ 2008-03-07 15:26 89024 C:\Programme\SlySoft\AnyDVD\AnyDVD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeviceDiscovery]
--a------ 2003-05-21 19:37 229437 C:\Programme\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2003-06-25 12:24 49152 C:\Programme\Hewlett-Packard\HP Software Update\HPWuSchd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
--a------ 2003-06-26 14:17 188416 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
--a------ 2007-05-11 02:08 2512392 C:\WINDOWS\system32\oodtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wscsvc"=2 (0x2)
"LxrSII1s"=2 (0x2)
"wuauserv"=2 (0x2)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"AlcoholAutomount"="C:\Programme\Alcohol Soft\Alcohol 120\axcmd.exe" /automount

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="C:\Programme\QuickTime\qttask.exe" -atboottime
"UpdReg"=C:\WINDOWS\UpdReg.EXE
"Adobe Reader Speed Launcher"="C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"CTxfiHlp"=CTXFIHLP.EXE

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programme\\Bonjour\\mDNSResponder.exe"=
"C:\\Programme\\uTorrent\\uTorrent.exe"=
"D:\\Pro Evolution Soccer 2008\\PES2008.exe"=
"C:\\Programme\\ICQLite\\ICQLite.exe"=

R2 CTAudSvcService;Creative Audio Service;C:\Programme\Creative\Shared Files\CTAudSvc.exe [2008-03-07 20:24]
R2 LxrSII1d;Secure II Driver;C:\WINDOWS\system32\Drivers\LxrSII1d.sys [2006-12-14 10:37]
R2 NMSAccessU;NMSAccessU;C:\Programme\CDBurnerXP\NMSAccessU.exe [2007-10-12 09:34]
R2 UxTuneUp;TuneUp Designerweiterung;C:\WINDOWS\System32\svchost.exe [2004-08-04 00:58]
R3 ha20x2k;Creative 20X HAL Driver;C:\WINDOWS\system32\drivers\ha20x2k.sys [2008-02-25 10:44]
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;C:\WINDOWS\system32\DRIVERS\RTL8187.sys [2006-06-16 09:30]
S3 TuneUp.Defrag;TuneUp Drive Defrag-Dienst;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-04-14 16:03]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{25584aea-0633-11dd-9107-0018f3645f89}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL DVR/AutoRun.exe start.exe

*Newly Created Service* - CATCHME

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B9482BB3-D290-B4EC-C404-A72331581690}]
C:\WINDOWS\system32\winamp.exe
.
Inhalt des "geplante Tasks" Ordners
"2008-04-19 21:00:00 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Programme\TuneUp Utilities 2008\OneClickStarter.exe
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-19 23:36:21
Windows 5.1.2600 Service Pack 2 NTFS

Scanne versteckte Prozesse...

Scanne versteckte Autostart Einträge...

Scanne versteckte Dateien...

Scan erfolgreich abgeschlossen
versteckte Dateien: 0

**************************************************************************
.
Zeit der Fertigstellung: 2008-04-19 23:37:01
ComboFix-quarantined-files.txt 2008-04-19 21:36:37
ComboFix2.txt 2008-04-18 08:38:47

10 Verzeichnis(se), 5,477,318,656 Bytes frei
12 Verzeichnis(se), 5,493,096,448 Bytes frei

oWn4g3
2008-04-20, 00:07
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Sunday, April 20, 2008 12:03:49 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 19/04/2008
Kaspersky Anti-Virus database records: 715802
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - Folders:
C:\

Scan Statistics:
Total number of scanned objects: 63394
Number of viruses found: 5
Number of infected objects: 6
Number of suspicious objects: 0
Duration of the scan process: 00:18:06

Infected Object Name / Virus Name / Last Action
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ESET\ESET Smart Security\Charon\CACHE.NDB Object is locked skipped
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ESET\ESET Smart Security\Logs\epfwlog.dat Object is locked skipped
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ESET\ESET Smart Security\Logs\virlog.dat Object is locked skipped
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ESET\ESET Smart Security\Logs\warnlog.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Cookies\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Verlauf\History.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\NTUSER.DAT Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\NTUSER.DAT Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\oWn4g3\Cookies\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Anwendungsdaten\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Verlauf\History.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Verlauf\History.IE5\MSHist012008041920080420\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\oWn4g3\NTUSER.DAT Object is locked skipped
C:\Dokumente und Einstellungen\oWn4g3\ntuser.dat.LOG Object is locked skipped
C:\Programme\Alcohol Soft\Alcohol 120\StarWind\logs\sw_ae-20080419-225745.log Object is locked skipped
C:\Programme\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.631 skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\hjrpanhj.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.pim skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\inomkxmb.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.pik skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\ltrfsmvk.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.pjx skipped
C:\QooBox\Quarantine\catchme2008-04-18_103304,32.zip/ddcCVPif.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.pki skipped
C:\QooBox\Quarantine\catchme2008-04-18_103304,32.zip ZIP: infected - 1 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{3574B6F9-47AC-4E3F-9F4E-69795126CC8B}\RP2\change.log Object is locked skipped
C:\WINDOWS\CSC\00000001 Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\S96B3E77A.tmp Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

Scan process completed.



Seems like something is still infected.

Blade81
2008-04-20, 00:29
Hi

Yes, let's take another run and remove those 4 files you got scanned. I'm not convinced that those other 3 are clean either.

This time let's do the run in safe mode since it seems resident protection prevents ComboFix from operating correctly. Before that save/print these instructions since you won't be able to access them while in safe mode.

Reboot into safe mode (http://www.computerhope.com/issues/chsafe.htm#02).

While in safe mode open notepad and copy/paste the text in the quotebox below into it:



KILLALL::

File::
C:\WINDOWS\system32\tpjaohmc.ini
C:\WINDOWS\system32\hsaodgyr.ini
C:\WINDOWS\system32\urqOHWPG.dll_old
C:\WINDOWS\system32\ati2sgav.exe
C:\WINDOWS\system32\tflvpiln.ini
C:\WINDOWS\BM1f718f8f.xml
C:\WINDOWS\system32\winamp.exe
C:\WINDOWS\UnGins.exe
C:\xdfe52.dll
C:\atm.dll
C:\UNACE.dll

Folder::
C:\Programme\tempa

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BA7CB974-956C-456A-BB82-BEEC3B5E1750}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ati2sgav"=-
"BM1f718f8f"=-

[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcBrRLf]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{25584aea-0633-11dd-9107-0018f3645f89}]

[-HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B9482BB3-D290-B4EC-C404-A72331581690}]



Save this as
CFScript


http://users.pandora.be/bluepatchy/miekiemoes/images/CFScript.gif

Refering to the picture above, drag CFScript into ComboFix.exe
Then reboot back into normal mode and post the resultant log (c:\ComboFix\ComboFix.txt contents) & a fresh hjt log.

oWn4g3
2008-04-20, 01:11
ComboFix 08-04-16.5 - oWn4g3 2008-04-20 1:05:35.3 - NTFSx86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1031.18.1776 [GMT 2:00]
ausgeführt von:: C:\Dokumente und Einstellungen\oWn4g3\Desktop\ComboFix.exe
Command switches used :: C:\Dokumente und Einstellungen\oWn4g3\Desktop\CFScript.txt

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\atm.dll
C:\UNACE.dll
C:\WINDOWS\BM1f718f8f.xml
C:\WINDOWS\system32\ati2sgav.exe
C:\WINDOWS\system32\hsaodgyr.ini
C:\WINDOWS\system32\tflvpiln.ini
C:\WINDOWS\system32\tpjaohmc.ini
C:\WINDOWS\system32\urqOHWPG.dll_old
C:\WINDOWS\system32\winamp.exe
C:\WINDOWS\UnGins.exe
C:\xdfe52.dll
.

(((((((((((((((((((((((((((((((((((( Weitere L”schungen ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\atm.dll
C:\Programme\tempa
C:\UNACE.dll
C:\WINDOWS\BM1f718f8f.xml
C:\WINDOWS\system32\ati2sgav.exe
C:\WINDOWS\system32\hsaodgyr.ini
C:\WINDOWS\system32\tflvpiln.ini
C:\WINDOWS\system32\tpjaohmc.ini
C:\WINDOWS\system32\urqOHWPG.dll_old
C:\WINDOWS\system32\winamp.exe
C:\WINDOWS\UnGins.exe
C:\xdfe52.dll

.
((((((((((((((((((((((( Dateien erstellt von 2008-03-19 bis 2008-04-19 ))))))))))))))))))))))))))))))
.

2008-04-17 22:50 . 2008-04-18 10:10 <DIR> d-------- C:\Programme\Hamachi
2008-04-17 19:15 . 2008-04-17 19:15 <DIR> d-------- C:\Programme\Pivot Stickfigure Animator
2008-04-16 14:45 . 2008-04-19 23:03 <DIR> d-------- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TrackMania
2008-04-16 10:15 . 2008-04-16 10:15 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-04-16 10:15 . 2008-04-16 10:15 <DIR> d-------- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Kaspersky Lab
2008-04-16 09:56 . 2008-04-16 09:56 <DIR> d-------- C:\Programme\Trend Micro
2008-04-15 16:30 . 2008-04-15 16:30 <DIR> d-------- C:\WINDOWS\nview
2008-04-15 16:30 . 2008-04-15 16:30 <DIR> d-------- C:\WINDOWS\nvidia icons
2008-04-15 16:30 . 2008-03-24 11:27 442,368 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2008-04-15 16:30 . 2008-03-24 19:52 442,368 --a------ C:\WINDOWS\system32\nvudisp.exe
2008-04-15 16:30 . 2008-04-20 01:08 175,605 --a------ C:\WINDOWS\system32\nvapps.xml
2008-04-15 16:30 . 2008-03-24 19:52 17,937 --a------ C:\WINDOWS\system32\nvdisp.nvu
2008-04-15 16:29 . 2008-04-15 16:29 <DIR> d-------- C:\NVIDIA
2008-04-14 16:07 . 2008-04-15 20:37 559 --a------ C:\WINDOWS\wininit.ini
2008-04-14 16:03 . 2008-04-14 16:03 307,968 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
2008-04-14 16:02 . 2008-02-27 13:15 28,416 --a------ C:\WINDOWS\system32\uxtuneup.dll
2008-04-13 14:15 . 2008-04-13 14:16 <DIR> d-------- C:\WINDOWS\Sins Bonuspack
2008-04-11 21:36 . 2008-04-13 14:49 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-11 21:36 . 2008-04-11 21:36 1,409 --a------ C:\WINDOWS\QTFont.for
2008-04-11 17:07 . 2008-04-11 17:07 <DIR> d-------- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Ubisoft
2008-04-09 14:33 . 2008-04-09 14:33 <DIR> d-------- C:\WINDOWS\.jagex_cache_32
2008-04-03 01:26 . 2008-04-03 01:26 41,296 --a------ C:\WINDOWS\system32\xfcodec.dll
2008-03-27 17:17 . 2008-03-27 21:21 <DIR> d-------- C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Command & Conquer 3 Kanes Rache
2008-03-27 00:04 . 2008-04-05 01:41 <DIR> d---s---- C:\Programme\HLSW
2008-03-27 00:04 . 2008-04-05 02:52 <DIR> d-------- C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\HLSW
2008-03-26 18:26 . 2008-03-26 18:26 <DIR> d-------- C:\Programme\OpenOffice.org 2.4
2008-03-25 15:38 . 2008-03-25 15:38 34,198 --a------ C:\Star Wars Battlefront II .mds
2008-03-24 16:25 . 2008-03-25 15:42 3,914,283,008 --a------ C:\Star Wars Battlefront II .mdf
2008-03-23 18:05 . 2008-03-23 18:05 122 --a------ C:\WINDOWS\WA.INI
2008-03-23 18:04 . 2008-03-23 18:04 1,559,605 --a------ C:\WINDOWS\WANEUninstaller.exe
2008-03-23 15:36 . 2008-03-23 15:36 <DIR> d-------- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Age of Empires 3
2008-03-20 18:06 . 2008-03-20 18:06 <DIR> d-------- C:\WINDOWS\PreviewSoft
2008-03-20 18:06 . 2008-03-20 18:06 <DIR> d-------- C:\WINDOWS\Noslip
2008-03-20 18:06 . 2008-03-20 18:06 <DIR> d-------- C:\Programme\Ulead GIF Animator 5
2008-03-20 18:06 . 1999-10-15 13:50 1,056,768 --a------ C:\WINDOWS\system32\ROBOEX32.DLL
2008-03-20 18:06 . 1999-01-28 16:44 49,152 --a------ C:\WINDOWS\system32\INETWH32.dll
2008-03-20 18:06 . 2008-03-20 18:06 4,808 --a------ C:\WINDOWS\system32\gaeffect.sti
2008-03-20 18:06 . 2008-03-20 18:06 3,176 --a------ C:\WINDOWS\system32\gafilter.sti
2008-03-20 18:06 . 2008-03-20 20:50 550 --ah----- C:\os466477.bin
2008-03-20 18:06 . 2008-03-20 20:50 449 --ah----- C:\WINDOWS\system32\ws344069.ocx
2008-03-20 18:06 . 2008-03-20 20:50 312 --a------ C:\WINDOWS\ULEAD32.INI
2008-03-19 16:18 . 2008-03-19 16:18 <DIR> d-------- C:\Programme\Latein-W”rterbuch

.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-19 22:45 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Xfire
2008-04-19 14:44 --------- d-----w C:\Programme\BOINC
2008-04-19 14:10 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\teamspeak2
2008-04-19 10:44 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\OpenOffice.org2
2008-04-19 10:18 --------- d-----w C:\Programme\Mozilla Thunderbird
2008-04-19 09:31 --------- d-s---w C:\Programme\Xfire
2008-04-18 14:14 --------- d-----w C:\Programme\PowerArchiver
2008-04-17 22:41 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Hamachi
2008-04-17 20:52 16,224 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys
2008-04-17 17:17 --------- d-----w C:\Programme\Trillian
2008-04-16 12:55 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Skype
2008-04-16 11:08 --------- d-----w C:\Programme\Gemeinsame Dateien\Wise Installation Wizard
2008-04-16 08:13 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\uTorrent
2008-04-15 19:27 --------- d-----w C:\Programme\mIRC
2008-04-15 19:27 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\mIRC
2008-04-15 17:11 --------- d-----w C:\Programme\Gemeinsame Dateien\Nero
2008-04-14 14:03 --------- d-----w C:\Programme\TuneUp Utilities 2008
2008-04-13 12:07 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Free Download Manager
2008-04-11 15:07 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-04-11 15:07 22,328 ----a-w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\PnkBstrK.sys
2008-04-11 14:55 --------- d--h--w C:\Programme\InstallShield Installation Information
2008-04-10 16:10 --------- d-----w C:\Programme\SpeedFan
2008-03-31 16:16 --------- d-----w C:\Programme\Winamp
2008-03-31 16:16 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Winamp
2008-03-24 17:52 6,547,872 ----a-w C:\WINDOWS\system32\drivers\nv4_mini.sys
2008-03-19 14:18 --------- d-----w C:\Programme\Latein-Wörterbuch
2008-03-17 16:35 --------- d-----w C:\Programme\Java
2008-03-16 12:50 --------- d-----w C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Creative
2008-03-16 12:40 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Creative
2008-03-14 09:38 --------- d-----w C:\Programme\Audacity
2008-03-09 19:02 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Media Player Classic
2008-03-09 19:01 --------- d-----w C:\Programme\XP Codec Pack
2008-03-07 13:24 97,216 ----a-w C:\WINDOWS\system32\drivers\AnyDVD.sys
2008-03-02 19:27 --------- d---a-w C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP
2008-03-02 10:12 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\dvdcss
2008-02-29 09:21 --------- d-----w C:\Programme\AGEIA Technologies
2008-02-25 19:32 --------- d-----w C:\Programme\DivX
2008-02-25 08:45 189,464 ----a-w C:\WINDOWS\system32\drivers\haP17v2k.sys
2008-02-25 08:45 15,896 ----a-w C:\WINDOWS\system32\drivers\pfmodnt.sys
2008-02-25 08:44 92,696 ----a-w C:\WINDOWS\system32\drivers\emupia2k.sys
2008-02-25 08:44 797,720 ----a-w C:\WINDOWS\system32\drivers\ha10kx2k.sys
2008-02-25 08:44 162,840 ----a-w C:\WINDOWS\system32\drivers\haP16v2k.sys
2008-02-25 08:44 157,208 ----a-w C:\WINDOWS\system32\drivers\ctsfm2k.sys
2008-02-25 08:44 14,360 ----a-w C:\WINDOWS\system32\drivers\ctprxy2k.sys
2008-02-25 08:44 1,172,504 ----a-w C:\WINDOWS\system32\drivers\ha20x2k.sys
2008-02-25 08:43 524,312 ----a-w C:\WINDOWS\system32\drivers\ctaud2k.sys
2008-02-25 08:43 511,000 ----a-w C:\WINDOWS\system32\drivers\ctac32k.sys
2008-02-25 08:43 346,856 ----a-w C:\WINDOWS\system32\drivers\ctdvda2k.sys
2008-02-25 08:43 18,840 ----a-w C:\WINDOWS\system32\drivers\CTGAME.SYS
2008-02-25 08:43 127,000 ----a-w C:\WINDOWS\system32\drivers\ctoss2k.sys
2008-02-25 08:43 1,372,568 ----a-w C:\WINDOWS\system32\drivers\CTMMFILT.SYS
2008-02-25 08:43 1,366,424 ----a-w C:\WINDOWS\system32\drivers\CT0531FL.SYS
2008-02-20 18:52 --------- d-----w C:\Programme\Unity
.

((((((((((((((((((((((((((((( snapshot@2008-04-18_10.38.32.46 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-18 08:34:41 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-19 23:08:18 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2008-03-30 09:24:10 70,778 ----a-w C:\WINDOWS\system32\perfc007.dat
+ 2008-04-18 08:39:15 70,778 ----a-w C:\WINDOWS\system32\perfc007.dat
- 2008-03-30 09:24:10 58,732 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-04-18 08:39:15 58,732 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-03-30 09:24:10 405,448 ----a-w C:\WINDOWS\system32\perfh007.dat
+ 2008-04-18 08:39:15 405,448 ----a-w C:\WINDOWS\system32\perfh007.dat
- 2008-03-30 09:24:10 392,432 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-04-18 08:39:15 392,432 ----a-w C:\WINDOWS\system32\perfh009.dat
.
(((((((((((((((((((((((((((( Autostart Punkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Hinweis* leere Eintrage & legitime Standardeintrage werden nicht angezeigt.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Pro Agent"="C:\Programme\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 15:08 136136]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:57 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Programme\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"Launch LCDMon"="C:\Programme\Gemeinsame Dateien\Logitech\LCD Manager\lcdmon.exe" [2007-04-26 17:54 774168]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 16:32 56080 C:\WINDOWS\KHALMNPR.Exe]
"VolPanel"="C:\Programme\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" [2006-07-13 15:11 122880]
"AudioDrvEmulator"="C:\Programme\Creative\Shared Files\Module Loader\DLLML.exe" [2005-11-04 19:07 49152]
"egui"="C:\Programme\ESET\ESET Smart Security\egui.exe" [2007-12-21 09:21 1443072]
"CTHelper"="CTHELPER.EXE" [2008-02-20 21:58 19456 C:\WINDOWS\system32\CtHelper.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-03-24 19:52 13524992]
"nwiz"="nwiz.exe" [2008-03-24 19:52 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-03-24 19:52 86016]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
--a------ 2008-03-07 15:26 89024 C:\Programme\SlySoft\AnyDVD\AnyDVD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeviceDiscovery]
--a------ 2003-05-21 19:37 229437 C:\Programme\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2003-06-25 12:24 49152 C:\Programme\Hewlett-Packard\HP Software Update\HPWuSchd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
--a------ 2003-06-26 14:17 188416 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
--a------ 2007-05-11 02:08 2512392 C:\WINDOWS\system32\oodtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wscsvc"=2 (0x2)
"LxrSII1s"=2 (0x2)
"wuauserv"=2 (0x2)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"AlcoholAutomount"="C:\Programme\Alcohol Soft\Alcohol 120\axcmd.exe" /automount

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="C:\Programme\QuickTime\qttask.exe" -atboottime
"UpdReg"=C:\WINDOWS\UpdReg.EXE
"Adobe Reader Speed Launcher"="C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"CTxfiHlp"=CTXFIHLP.EXE

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programme\\Bonjour\\mDNSResponder.exe"=
"C:\\Programme\\uTorrent\\uTorrent.exe"=
"D:\\Pro Evolution Soccer 2008\\PES2008.exe"=
"C:\\Programme\\ICQLite\\ICQLite.exe"=

R2 CTAudSvcService;Creative Audio Service;C:\Programme\Creative\Shared Files\CTAudSvc.exe [2008-03-07 20:24]
R2 LxrSII1d;Secure II Driver;C:\WINDOWS\system32\Drivers\LxrSII1d.sys [2006-12-14 10:37]
R2 NMSAccessU;NMSAccessU;C:\Programme\CDBurnerXP\NMSAccessU.exe [2007-10-12 09:34]
R2 UxTuneUp;TuneUp Designerweiterung;C:\WINDOWS\System32\svchost.exe [2004-08-04 00:58]
R3 ha20x2k;Creative 20X HAL Driver;C:\WINDOWS\system32\drivers\ha20x2k.sys [2008-02-25 10:44]
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;C:\WINDOWS\system32\DRIVERS\RTL8187.sys [2006-06-16 09:30]
S3 TuneUp.Defrag;TuneUp Drive Defrag-Dienst;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-04-14 16:03]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

.
Inhalt des "geplante Tasks" Ordners
"2008-04-19 23:08:20 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Programme\TuneUp Utilities 2008\OneClickStarter.exe
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-20 01:08:32
Windows 5.1.2600 Service Pack 2 NTFS

Scanne versteckte Prozesse...

Scanne versteckte Autostart Eintr„ge...

Scanne versteckte Dateien...

Scan erfolgreich abgeschlossen
versteckte Dateien: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\CTxfispi.exe
C:\Programme\Logitech\SetPoint\SetPoint.exe
C:\Programme\Gemeinsame Dateien\Logitech\KhalShared\KHALMNPR.exe
C:\Programme\Gemeinsame Dateien\Logitech\LCD Manager\Applets\LCDClock.exe
C:\Programme\Gemeinsame Dateien\Logitech\LCD Manager\Applets\LCDMedia.exe
C:\Programme\Bonjour\mDNSResponder.exe
C:\Programme\Eset\ESET Smart Security\ekrn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Programme\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2008-04-20 1:10:36 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-19 23:10:28
ComboFix2.txt 2008-04-19 21:37:02
ComboFix3.txt 2008-04-18 08:38:47

10 Verzeichnis(se), 5,574,819,840 Bytes frei
12 Verzeichnis(se), 5,565,333,504 Bytes frei

oWn4g3
2008-04-20, 01:12
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 01:11:50, on 20.04.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\Creative\Shared Files\CTAudSvc.exe
C:\Programme\Java\jre1.6.0_05\bin\jusched.exe
C:\Programme\Gemeinsame Dateien\Logitech\LCD Manager\lcdmon.exe
C:\Programme\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
C:\Programme\Creative\Shared Files\Module Loader\DLLML.exe
C:\Programme\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Programme\DAEMON Tools Pro\DTProAgent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\Logitech\SetPoint\SetPoint.exe
C:\Programme\Gemeinsame Dateien\Logitech\KhalShared\KHALMNPR.EXE
C:\Programme\Gemeinsame Dateien\Logitech\LCD Manager\Applets\LCDClock.exe
C:\Programme\Gemeinsame Dateien\Logitech\LCD Manager\Applets\LCDMedia.exe
C:\Programme\Bonjour\mDNSResponder.exe
C:\Programme\ESET\ESET Smart Security\ekrn.exe
C:\Programme\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Programme\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Programme\Mozilla Firefox\firefox.exe
C:\Programme\Trend Micro\HijackThis\oWn4g3.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Programme\Gemeinsame Dateien\Logitech\LCD Manager\lcdmon.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [VolPanel] "C:\Programme\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Programme\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Programme\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [egui] "C:\Programme\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Programme\DAEMON Tools Pro\DTProAgent.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Programme\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Programme\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Programme\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Programme\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Programme\Free Download Manager\dllink.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V02002/ocx/15030/CTPID.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Programme\Bonjour\mDNSResponder.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Programme\Creative\Shared Files\CTAudSvc.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Programme\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Programme\ESET\ESET Smart Security\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programme\Gemeinsame Dateien\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Programme\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Programme\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: TuneUp Drive Defrag-Dienst (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

--
End of file - 7011 bytes

Hope these things help and thanks fpr alle the effort you put into the help :)

Blade81
2008-04-20, 01:28
Hi

Looks like that did the trick :)


Bad items are in QooBox folder (quarantine folder of ComboFix) and will get deleted when ComboFix is uninstalled (instructions below).


Well congrats, it appears your system is all clean Are you still noticing any problems? If not, it's time to secure your system to prevent against further intrusions.


THESE STEPS ARE VERY IMPORTANT

Let's reset system restore
Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: You will lose all previous restore points which are likely to be infected. Please note you need Administrator Access to do clean the restore points.

1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

2. Reboot.

3. Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.
NOTE: only do this ONCE,NOT on a regular basis


Now lets uninstall ComboFix:

Click START then RUN
Now type Combofix /u in the runbox and click OK




Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update to the latest version...

Updating Java:

Download the latest version of Java Runtime Environment (JRE) 6 Update 6 (http://java.sun.com/javase/downloads/index.jsp).
Scroll down to where it says
The J2SE Runtime Environment (JRE) allows end-users to run Java applications.

Click the
Download
button to the right.
Select Windows on platform combobox and check the box that says:
Accept License Agreement. Click continue.

The page will refresh.
Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
Close any programs you may have running - especially your web browser.
Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
Check any item with Java Runtime Environment (JRE or J2SE) in the name.
Click the Remove or Change/Remove button.
Repeat as many times as necessary to remove each Java versions.
Reboot your computer once all Java components are removed.
Then from your desktop double-click on jre-6u6-windows-i586-p.exe to install the newest version.


UPDATING WINDOWS AND INTERNET EXPLORER

IMPORTANT: You Need to Update Windows and Internet Explorer to protect your computer from the malware that is around on the Internet. Please go to the windows update site (http://windowsupdate.microsoft.com/) to get the critical updates.

If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.


Make your Internet Explorer more secure

This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialize and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt
When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.



The following are recommended third party programs that are designed to keep your computer clean. A link as well as a brief description is included with each item.

Comodo BOCLEAN (http://www.comodo.com/boclean/boclean.html) <= Stop identity thieves from getting personal information. Instantly detects well over 1,000,000 unique, variant and repack malware in total. And it's free.
Download Adaware
Adaware is a free program. It scans for known spyware on your computer. These scans should be run at least once every two weeks. For more information, see this tutorial (http://www.bleepingcomputer.com/forums/index.php?showtutorial=48)
The program is available for download here (http://www.download.com/Ad-Aware-SE-Personal-Edition/3000-8022_4-10319876.html?tag=lst-0-1)
Download Spybot
Spybot is a scanner like adaware. It scans for spyware and other malicious programs. It is important to have both Adaware and Spybot on your computer because each program provides unique detection and pretection measures. Spybot has preventitive tools that stop programs from even installing on your computer.
To see how to set this up as well as more spybot features, see here (http://www.bleepingcomputer.com/forums/index.php?showtutorial=43)
Spybot can be downloaded at this location (http://www.download.com/Spybot-Search-Destroy/3000-8022-10122137.html?part=dl-spybot&subj=dl&tag=but)
Download SpywareBlaster
Spyware blaster is a program that stops known malicious activex controls from installing on your computer. It works by changing settings in your registry. It makes
kill bits
in the registry, so that certain activex controls can't install.
If you don't know what activex controls are, see here (http://www.webopedia.com/TERM/A/ActiveX_control.html)
You can download SpywareBlaster here here (http://majorgeeks.com/downloadget.php?id=2859&file=11&evp=61b0e8ad41924a03c37615f4682b4cef)
SpywareBlaster tutorial (http://www.bleepingcomputer.com/forums/tutorial49.html)

Download iespyad
It puts many bad webpages on your restricted zones list. This means that you can still view the
bad
webpages, but the webpages cannot do certain things (such as use javascripts and cookies).
If you need help understanding how it works, there is a tutorial here (http://www.bleepingcomputer.com/tutorials/tutorial53.html)
Download it here (http://www.spywarewarrior.com/uiuc/res/ie-spyad.exe)

hosts file:
Every version of windows has a hosts file as part of them. In a very basic sense, they are used to locate webpages. We can customize a hosts file so that it blocks certain webpages. However, it can slow down certain computers. This is why using a hosts file is optional!!
Download it here (http://www.mvps.org/winhelp2002/hosts.htm). Make sure you read the instructions on how to install the hosts file. There is a good tutorial here (http://www.bleepingcomputer.com/forums/tutorial51.html)
If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
Click the start button (at the lower left hand corner of your screen) Click run In the dialog box, type services.msc hit enter, then locate dns client Highlight it, then double-click it. On the dropdown box, change the setting from automatic to manual. Click ok


Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For more info, check this (http://www.bleepingcomputer.com/forums/tutorial60.html) webpage out.
See here (http://www.freebyte.com/antivirus/#firewalls) to choose one unless you have a firewall in ESET product.



Just a final reminder for you. I am trying to stress these two points.
UPDATE UPDATE UPDATE!!! Make sure you do this about every 1-2 weeks.
Make sure all of your security programs are up to date.
Run the spybot and adaware regularly. (Once or twice a week minimum.)
Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.



Once again, please post and tell me how things are going with your system... problems etc.

Have a great day,
Blade :cool:

oWn4g3
2008-04-20, 01:44
Thank you so much, no missing .dll messages, firefox starting fast and everything else is okay.

Downloaded Adaware, the Java Update and Comodo BOCLEAN. I'm using the firefox so I changed nothing concerning the iexplorer. As a firewall I use the one one that is integrated in ESET Smart Security. I hope that it is effective, I just continued to belive in ESET as they never failed me with NOD32 :)
Combofix re-enabled the MS Security Center. Is it okay to disable it again as I dont like the symbol and the popups etc ?

Everything runs perfectly now, you really saved me :)
Thanks again and keep up the good work

Blade81
2008-04-20, 12:28
You're welcome :)

Yes, ESET Smart Security's firewall is ok. You can disable those Security Center notifications if you want.

oWn4g3
2008-04-21, 23:34
Okay, thank you again. Everything runs fine now.

Thread can be closed now :)

Blade81
2008-04-22, 06:29
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help. :)

Note:If it has been five days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than five days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required.