Page 1 of 2 12 LastLast
Results 1 to 10 of 17

Thread: Virtumonde Removal - Nr. X

  1. #1
    Junior Member
    Join Date
    Apr 2008
    Posts
    12

    Default Virtumonde Removal - Nr. X

    Hi, I'm the next in line I guess...
    I know its a lot of work but it would be very nice if someone helped me

    I have to start with a Spybot Log and a HJT Log right?

  2. #2
    Junior Member
    Join Date
    Apr 2008
    Posts
    12

    Default First Step

    I have renamed the HJT exe to own4g3.exe and made a scan and log


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 09:57:38, on 16.04.2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.5730.0013)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Programme\Creative\Shared Files\CTAudSvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\Programme\Java\jre1.6.0_05\bin\jusched.exe
    C:\Programme\Gemeinsame Dateien\Logitech\LCD Manager\lcdmon.exe
    C:\Programme\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
    C:\Programme\Creative\Shared Files\Module Loader\DLLML.exe
    C:\Programme\ESET\ESET Smart Security\egui.exe
    C:\WINDOWS\system32\CTHELPER.EXE
    C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Programme\Gemeinsame Dateien\Logitech\LCD Manager\Applets\LCDClock.exe
    C:\Programme\Gemeinsame Dateien\Logitech\LCD Manager\Applets\LCDMedia.exe
    C:\Programme\DAEMON Tools Pro\DTProAgent.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Programme\Bonjour\mDNSResponder.exe
    C:\Programme\Logitech\SetPoint\SetPoint.exe
    C:\Programme\ESET\ESET Smart Security\ekrn.exe
    C:\Programme\Internet Explorer\IEXPLORE.EXE
    C:\WINDOWS\system32\LxrSII1s.exe
    C:\Programme\CDBurnerXP\NMSAccessU.exe
    C:\Programme\Gemeinsame Dateien\Logitech\KhalShared\KHALMNPR.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\oodag.exe
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\WINDOWS\system32\PnkBstrB.exe
    C:\Programme\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Programme\Mozilla Firefox\firefox.exe
    C:\Programme\Spybot - Search & Destroy\SpybotSD.exe
    C:\Programme\Trend Micro\HijackThis\oWn4g3.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: {3d7fc2ea-8182-03f8-f2a4-5fd23b833a25} - {52a338b3-2df5-4a2f-8f30-2818ae2cf7d3} - C:\WINDOWS\system32\mbxtviru.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_05\bin\ssv.dll
    O2 - BHO: (no name) - {83545753-2A0F-438E-AB2F-6679BE9D1FBE} - C:\WINDOWS\system32\efcBrRLf.dll
    O2 - BHO: (no name) - {8D5A848F-AF4F-4588-BE54-3741AFDFCE55} - (no file)
    O2 - BHO: (no name) - {AB8A2536-8D9B-44F4-BE95-06F7B4610445} - C:\WINDOWS\system32\ddcCVPif.dll
    O2 - BHO: (no name) - {BA7CB974-956C-456A-BB82-BEEC3B5E1750} - C:\WINDOWS\system32\urqOHWPG.dll (file missing)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [Launch LCDMon] "C:\Programme\Gemeinsame Dateien\Logitech\LCD Manager\lcdmon.exe"
    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [VolPanel] "C:\Programme\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
    O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Programme\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Programme\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
    O4 - HKLM\..\Run: [egui] "C:\Programme\ESET\ESET Smart Security\egui.exe" /hide /waitservice
    O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
    O4 - HKLM\..\Run: [1c42bc13] rundll32.exe "C:\WINDOWS\system32\cmhoajpt.dll",b
    O4 - HKLM\..\Run: [ati2sgav] "C:\WINDOWS\system32\ati2sgav.exe"
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [NBKeyScan] "C:\Programme\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
    O4 - HKLM\..\Run: [BM1f718f8f] Rundll32.exe "C:\WINDOWS\system32\iaecjrpf.dll",s
    O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Programme\DAEMON Tools Pro\DTProAgent.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: Logitech SetPoint.lnk = C:\Programme\Logitech\SetPoint\SetPoint.exe
    O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Programme\Free Download Manager\dlall.htm
    O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Programme\Free Download Manager\dlselected.htm
    O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Programme\Free Download Manager\dlfvideo.htm
    O8 - Extra context menu item: Download with Free Download Manager - file://C:\Programme\Free Download Manager\dllink.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
    O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V020...5030/CTPID.cab
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL
    O20 - Winlogon Notify: efcBrRLf - C:\WINDOWS\SYSTEM32\efcBrRLf.dll
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Programme\Bonjour\mDNSResponder.exe
    O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Programme\Creative\Shared Files\CTAudSvc.exe
    O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Programme\ESET\ESET Smart Security\EHttpSrv.exe
    O23 - Service: Eset Service (ekrn) - ESET - C:\Programme\ESET\ESET Smart Security\ekrn.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programme\Gemeinsame Dateien\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Lexar Secure II (LxrSII1s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrSII1s.exe
    O23 - Service: NMSAccessU - Unknown owner - C:\Programme\CDBurnerXP\NMSAccessU.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
    O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Programme\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    O23 - Service: TuneUp Drive Defrag-Dienst (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

    --
    End of file - 8098 bytes

  3. #3
    Junior Member
    Join Date
    Apr 2008
    Posts
    12

    Default Addition

    Kaspersky Online Scan doesnt work. I click Accept but nothing happens... I can't even enter google anymore...

  4. #4
    Junior Member
    Join Date
    Apr 2008
    Posts
    12

    Default Kaspersky Online Scan

    Ok, got kaspersky Online running for 1:33 hours
    LOG:


    -------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER REPORT
    Wednesday, April 16, 2008 12:07:09 PM
    Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
    Kaspersky Online Scanner version: 5.0.98.0
    Kaspersky Anti-Virus database last update: 16/04/2008
    Kaspersky Anti-Virus database records: 709546
    -------------------------------------------------------------------------------

    Scan Settings:
    Scan using the following antivirus database: extended
    Scan Archives: true
    Scan Mail Bases: true

    Scan Target - My Computer:
    C:\
    D:\
    E:\
    F:\
    H:\
    I:\

    Scan Statistics:
    Total number of scanned objects: 322315
    Number of viruses found: 5
    Number of infected objects: 10
    Number of suspicious objects: 0
    Duration of the scan process: 01:33:30

    Infected Object Name / Virus Name / Last Action
    C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ESET\ESET Smart Security\Charon\CACHE.NDB Object is locked skipped
    C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ESET\ESET Smart Security\Logs\epfwlog.dat Object is locked skipped
    C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ESET\ESET Smart Security\Logs\virlog.dat Object is locked skipped
    C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ESET\ESET Smart Security\Logs\warnlog.dat Object is locked skipped
    C:\Dokumente und Einstellungen\LocalService\Cookies\index.dat Object is locked skipped
    C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Verlauf\History.IE5\index.dat Object is locked skipped
    C:\Dokumente und Einstellungen\LocalService\NTUSER.DAT Object is locked skipped
    C:\Dokumente und Einstellungen\LocalService\ntuser.dat.LOG Object is locked skipped
    C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Dokumente und Einstellungen\NetworkService\NTUSER.DAT Object is locked skipped
    C:\Dokumente und Einstellungen\NetworkService\ntuser.dat.LOG Object is locked skipped
    C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Mozilla\Firefox\Profiles\lkn2udva.default\cert8.db Object is locked skipped
    C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Mozilla\Firefox\Profiles\lkn2udva.default\flashgot.log Object is locked skipped
    C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Mozilla\Firefox\Profiles\lkn2udva.default\history.dat Object is locked skipped
    C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Mozilla\Firefox\Profiles\lkn2udva.default\key3.db Object is locked skipped
    C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Mozilla\Firefox\Profiles\lkn2udva.default\search.sqlite Object is locked skipped
    C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Mozilla\Firefox\Profiles\lkn2udva.default\urlclassifier2.sqlite Object is locked skipped
    C:\Dokumente und Einstellungen\oWn4g3\Cookies\index.dat Object is locked skipped
    C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Anwendungsdaten\Microsoft\Feeds Cache\index.dat Object is locked skipped
    C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Anwendungsdaten\Mozilla\Firefox\Profiles\lkn2udva.default\Cache\_CACHE_001_ Object is locked skipped
    C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Anwendungsdaten\Mozilla\Firefox\Profiles\lkn2udva.default\Cache\_CACHE_002_ Object is locked skipped
    C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Anwendungsdaten\Mozilla\Firefox\Profiles\lkn2udva.default\Cache\_CACHE_003_ Object is locked skipped
    C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Anwendungsdaten\Mozilla\Firefox\Profiles\lkn2udva.default\Cache\_CACHE_MAP_ Object is locked skipped
    C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
    C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Temporary Internet Files\Content.IE5\79GE3VAV\idkfa[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.okj skipped
    C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Temporary Internet Files\Content.IE5\XJT5D1R2\idkfa[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.okj skipped
    C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Verlauf\History.IE5\index.dat Object is locked skipped
    C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Verlauf\History.IE5\MSHist012008041620080417\index.dat Object is locked skipped
    C:\Dokumente und Einstellungen\oWn4g3\NTUSER.DAT Object is locked skipped
    C:\Dokumente und Einstellungen\oWn4g3\ntuser.dat.LOG Object is locked skipped
    C:\Programme\Alcohol Soft\Alcohol 120\StarWind\logs\sw_ae-20080416-091810.log Object is locked skipped
    C:\Programme\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.631 skipped
    C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
    C:\WINDOWS\CSC\00000001 Object is locked skipped
    C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
    C:\WINDOWS\S96B3E77A.tmp Object is locked skipped
    C:\WINDOWS\SchedLgU.Txt Object is locked skipped
    C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
    C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
    C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\default Object is locked skipped
    C:\WINDOWS\system32\config\default.LOG Object is locked skipped
    C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
    C:\WINDOWS\system32\config\SAM Object is locked skipped
    C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\SECURITY Object is locked skipped
    C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
    C:\WINDOWS\system32\config\software Object is locked skipped
    C:\WINDOWS\system32\config\software.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\system Object is locked skipped
    C:\WINDOWS\system32\config\system.LOG Object is locked skipped
    C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
    C:\WINDOWS\system32\h323log.txt Object is locked skipped
    C:\WINDOWS\system32\iaecjrpf.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.okj skipped
    C:\WINDOWS\system32\pbsvc.exe Infected: not-a-virus:AdWare.Win32.AdMedia.br skipped
    C:\WINDOWS\system32\vfkwwqpo.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.okj skipped
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
    E:\Software & Tools\mirc616.exe/data0001.bin Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
    E:\Software & Tools\mirc616.exe mIRC: infected - 1 skipped
    E:\Software & Tools\Nero 8 Ultra Edition 8.2.8.0\Nero-8.2.8.0_eng_trial.exe/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
    E:\Software & Tools\Nero 8 Ultra Edition 8.2.8.0\Nero-8.2.8.0_eng_trial.exe 7-Zip: infected - 1 skipped

    Scan process completed.


    Hope that these things will help. Virtumonde is quite annoying...

  5. #5
    Junior Member
    Join Date
    Apr 2008
    Posts
    12

    Default

    I thought that I might have been forgotten so I decided to do a ComboFix Scan.
    Here is the log:


    ComboFix 08-04-16.5 - oWn4g3 2008-04-18 10:30:33.1 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1031.18.1621 [GMT 2:00]
    ausgeführt von:: C:\Dokumente und Einstellungen\oWn4g3\Desktop\ComboFix.exe
    * Resident AV is active


    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .

    (((((((((((((((((((((((((((((((((((( Weitere L”schungen ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\WINDOWS\pskt.ini
    C:\WINDOWS\system32\bmxkmoni.ini
    C:\WINDOWS\system32\Cfx32.lic
    C:\WINDOWS\system32\cfx32.ocx
    C:\WINDOWS\system32\ddcCVPif.dll
    C:\WINDOWS\system32\efcBrRLf.dll
    C:\WINDOWS\system32\fgudcdgb.dll
    C:\WINDOWS\system32\fiPVCcdd.ini
    C:\WINDOWS\system32\fiPVCcdd.ini2
    C:\WINDOWS\system32\GPWHOqru.ini
    C:\WINDOWS\system32\GPWHOqru.ini2
    C:\WINDOWS\system32\hjrpanhj.dll
    C:\WINDOWS\system32\hvwdodic.dll
    C:\WINDOWS\system32\inomkxmb.dll
    C:\WINDOWS\system32\kvmsfrtl.ini
    C:\WINDOWS\system32\ltrfsmvk.dll
    C:\WINDOWS\system32\mbxtviru.dll
    C:\WINDOWS\system32\mcrh.tmp
    C:\WINDOWS\system32\xbbeNqru.ini
    C:\WINDOWS\system32\xbbeNqru.ini2

    .
    ((((((((((((((((((((((( Dateien erstellt von 2008-03-18 bis 2008-04-18 ))))))))))))))))))))))))))))))
    .

    2008-04-17 22:50 . 2008-04-18 10:10 <DIR> d-------- C:\Programme\Hamachi
    2008-04-17 19:15 . 2008-04-17 19:15 <DIR> d-------- C:\Programme\Pivot Stickfigure Animator
    2008-04-16 14:45 . 2008-04-17 17:59 <DIR> d-------- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TrackMania
    2008-04-16 10:15 . 2008-04-16 10:15 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
    2008-04-16 10:15 . 2008-04-16 10:15 <DIR> d-------- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Kaspersky Lab
    2008-04-16 09:56 . 2008-04-16 09:56 <DIR> d-------- C:\Programme\Trend Micro
    2008-04-16 09:26 . 2008-04-17 09:26 414 ---hs---- C:\WINDOWS\system32\tpjaohmc.ini
    2008-04-15 16:30 . 2008-04-15 16:30 <DIR> d-------- C:\WINDOWS\nview
    2008-04-15 16:30 . 2008-04-15 16:30 <DIR> d-------- C:\WINDOWS\nvidia icons
    2008-04-15 16:30 . 2008-03-24 11:27 442,368 --a------ C:\WINDOWS\system32\NVUNINST.EXE
    2008-04-15 16:30 . 2008-03-24 19:52 442,368 --a------ C:\WINDOWS\system32\nvudisp.exe
    2008-04-15 16:30 . 2008-04-18 10:36 175,605 --a------ C:\WINDOWS\system32\nvapps.xml
    2008-04-15 16:30 . 2008-03-24 19:52 17,937 --a------ C:\WINDOWS\system32\nvdisp.nvu
    2008-04-15 16:29 . 2008-04-15 16:29 <DIR> d-------- C:\NVIDIA
    2008-04-15 14:56 . 2008-04-15 21:09 594 ---hs---- C:\WINDOWS\system32\hsaodgyr.ini
    2008-04-15 14:47 . 2008-04-15 14:47 272,384 --------- C:\WINDOWS\system32\urqOHWPG.dll_old
    2008-04-14 19:48 . 2008-04-15 14:42 <DIR> d-------- C:\Programme\tempa
    2008-04-14 19:48 . 2008-04-08 11:50 206,191 --a------ C:\WINDOWS\system32\ati2sgav.exe
    2008-04-14 16:07 . 2008-04-15 20:37 559 --a------ C:\WINDOWS\wininit.ini
    2008-04-14 16:03 . 2008-04-14 16:03 307,968 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
    2008-04-14 16:02 . 2008-02-27 13:15 28,416 --a------ C:\WINDOWS\system32\uxtuneup.dll
    2008-04-14 07:20 . 2008-04-14 16:26 354 ---hs---- C:\WINDOWS\system32\tflvpiln.ini
    2008-04-14 07:12 . 2008-04-17 08:54 101,091 --a------ C:\WINDOWS\BM1f718f8f.xml
    2008-04-13 14:15 . 2008-04-13 14:16 <DIR> d-------- C:\WINDOWS\Sins Bonuspack
    2008-04-11 21:36 . 2008-04-13 14:49 54,156 --ah----- C:\WINDOWS\QTFont.qfn
    2008-04-11 21:36 . 2008-04-11 21:36 1,409 --a------ C:\WINDOWS\QTFont.for
    2008-04-11 17:07 . 2008-04-11 17:07 <DIR> d-------- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Ubisoft
    2008-04-11 16:54 . 2008-04-14 19:48 441,652 --a------ C:\WINDOWS\system32\winamp.exe
    2008-04-09 14:33 . 2008-04-09 14:33 <DIR> d-------- C:\WINDOWS\.jagex_cache_32
    2008-04-06 12:39 . 2000-07-08 15:06 87,040 --a------ C:\WINDOWS\UnGins.exe
    2008-04-06 12:34 . 2008-04-06 12:34 457,728 --a------ C:\xdfe52.dll
    2008-04-06 12:34 . 2008-04-06 12:34 69,120 --a------ C:\atm.dll
    2008-04-06 12:34 . 2008-04-06 12:34 45,056 --a------ C:\UNACE.dll
    2008-04-03 01:26 . 2008-04-03 01:26 41,296 --a------ C:\WINDOWS\system32\xfcodec.dll
    2008-03-27 17:17 . 2008-03-27 21:21 <DIR> d-------- C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Command & Conquer 3 Kanes Rache
    2008-03-27 00:04 . 2008-04-05 01:41 <DIR> d---s---- C:\Programme\HLSW
    2008-03-27 00:04 . 2008-04-05 02:52 <DIR> d-------- C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\HLSW
    2008-03-26 18:26 . 2008-03-26 18:26 <DIR> d-------- C:\Programme\OpenOffice.org 2.4
    2008-03-25 15:38 . 2008-03-25 15:38 34,198 --a------ C:\Star Wars Battlefront II .mds
    2008-03-24 16:25 . 2008-03-25 15:42 3,914,283,008 --a------ C:\Star Wars Battlefront II .mdf
    2008-03-23 18:05 . 2008-03-23 18:05 122 --a------ C:\WINDOWS\WA.INI
    2008-03-23 18:04 . 2008-03-23 18:04 1,559,605 --a------ C:\WINDOWS\WANEUninstaller.exe
    2008-03-23 15:36 . 2008-03-23 15:36 <DIR> d-------- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Age of Empires 3
    2008-03-20 18:06 . 2008-03-20 18:06 <DIR> d-------- C:\WINDOWS\PreviewSoft
    2008-03-20 18:06 . 2008-03-20 18:06 <DIR> d-------- C:\WINDOWS\Noslip
    2008-03-20 18:06 . 2008-03-20 18:06 <DIR> d-------- C:\Programme\Ulead GIF Animator 5
    2008-03-20 18:06 . 1999-10-15 13:50 1,056,768 --a------ C:\WINDOWS\system32\ROBOEX32.DLL
    2008-03-20 18:06 . 1999-01-28 16:44 49,152 --a------ C:\WINDOWS\system32\INETWH32.dll
    2008-03-20 18:06 . 2008-03-20 18:06 4,808 --a------ C:\WINDOWS\system32\gaeffect.sti
    2008-03-20 18:06 . 2008-03-20 18:06 3,176 --a------ C:\WINDOWS\system32\gafilter.sti
    2008-03-20 18:06 . 2008-03-20 20:50 550 --ah----- C:\os466477.bin
    2008-03-20 18:06 . 2008-03-20 20:50 449 --ah----- C:\WINDOWS\system32\ws344069.ocx
    2008-03-20 18:06 . 2008-03-20 20:50 312 --a------ C:\WINDOWS\ULEAD32.INI
    2008-03-19 16:18 . 2008-03-19 16:18 <DIR> d-------- C:\Programme\Latein-W”rterbuch
    2008-03-18 18:42 . 2008-04-17 22:47 <DIR> d-------- C:\temp

    .
    (((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-04-17 22:42 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Xfire
    2008-04-17 22:41 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Hamachi
    2008-04-17 20:52 16,224 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys
    2008-04-17 17:17 --------- d-----w C:\Programme\Trillian
    2008-04-17 17:15 --------- d-----w C:\Programme\PowerArchiver
    2008-04-17 17:11 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\teamspeak2
    2008-04-17 14:16 --------- d-s---w C:\Programme\Xfire
    2008-04-17 14:14 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\OpenOffice.org2
    2008-04-17 07:11 --------- d-----w C:\Programme\BOINC
    2008-04-16 12:55 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Skype
    2008-04-16 11:08 --------- d-----w C:\Programme\Gemeinsame Dateien\Wise Installation Wizard
    2008-04-16 10:14 --------- d-----w C:\Programme\Mozilla Thunderbird
    2008-04-16 08:13 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\uTorrent
    2008-04-15 19:27 --------- d-----w C:\Programme\mIRC
    2008-04-15 19:27 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\mIRC
    2008-04-15 17:11 --------- d-----w C:\Programme\Gemeinsame Dateien\Nero
    2008-04-14 14:03 --------- d-----w C:\Programme\TuneUp Utilities 2008
    2008-04-13 12:07 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Free Download Manager
    2008-04-11 15:07 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
    2008-04-11 15:07 22,328 ----a-w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\PnkBstrK.sys
    2008-04-11 14:55 --------- d--h--w C:\Programme\InstallShield Installation Information
    2008-04-10 16:10 --------- d-----w C:\Programme\SpeedFan
    2008-03-31 16:16 --------- d-----w C:\Programme\Winamp
    2008-03-31 16:16 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Winamp
    2008-03-24 17:52 6,547,872 ----a-w C:\WINDOWS\system32\drivers\nv4_mini.sys
    2008-03-19 14:18 --------- d-----w C:\Programme\Latein-Wörterbuch
    2008-03-17 16:35 --------- d-----w C:\Programme\Java
    2008-03-16 12:50 --------- d-----w C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Creative
    2008-03-16 12:40 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Creative
    2008-03-14 09:38 --------- d-----w C:\Programme\Audacity
    2008-03-09 19:02 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Media Player Classic
    2008-03-09 19:01 --------- d-----w C:\Programme\XP Codec Pack
    2008-03-07 13:24 97,216 ----a-w C:\WINDOWS\system32\drivers\AnyDVD.sys
    2008-03-02 19:27 --------- d---a-w C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP
    2008-03-02 10:12 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\dvdcss
    2008-02-29 09:21 --------- d-----w C:\Programme\AGEIA Technologies
    2008-02-25 19:32 --------- d-----w C:\Programme\DivX
    2008-02-25 08:45 189,464 ----a-w C:\WINDOWS\system32\drivers\haP17v2k.sys
    2008-02-25 08:45 15,896 ----a-w C:\WINDOWS\system32\drivers\pfmodnt.sys
    2008-02-25 08:44 92,696 ----a-w C:\WINDOWS\system32\drivers\emupia2k.sys
    2008-02-25 08:44 797,720 ----a-w C:\WINDOWS\system32\drivers\ha10kx2k.sys
    2008-02-25 08:44 162,840 ----a-w C:\WINDOWS\system32\drivers\haP16v2k.sys
    2008-02-25 08:44 157,208 ----a-w C:\WINDOWS\system32\drivers\ctsfm2k.sys
    2008-02-25 08:44 14,360 ----a-w C:\WINDOWS\system32\drivers\ctprxy2k.sys
    2008-02-25 08:44 1,172,504 ----a-w C:\WINDOWS\system32\drivers\ha20x2k.sys
    2008-02-25 08:43 524,312 ----a-w C:\WINDOWS\system32\drivers\ctaud2k.sys
    2008-02-25 08:43 511,000 ----a-w C:\WINDOWS\system32\drivers\ctac32k.sys
    2008-02-25 08:43 346,856 ----a-w C:\WINDOWS\system32\drivers\ctdvda2k.sys
    2008-02-25 08:43 18,840 ----a-w C:\WINDOWS\system32\drivers\CTGAME.SYS
    2008-02-25 08:43 127,000 ----a-w C:\WINDOWS\system32\drivers\ctoss2k.sys
    2008-02-25 08:43 1,372,568 ----a-w C:\WINDOWS\system32\drivers\CTMMFILT.SYS
    2008-02-25 08:43 1,366,424 ----a-w C:\WINDOWS\system32\drivers\CT0531FL.SYS
    2008-02-20 18:52 --------- d-----w C:\Programme\Unity
    2008-02-18 18:05 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\ESET
    2008-02-18 18:03 --------- d-----w C:\Programme\Eset
    2008-02-18 18:03 --------- d-----w C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ESET
    2008-02-18 17:30 --------- d-----w C:\Programme\Xvid
    2008-02-18 17:28 --------- d-----w C:\Programme\FreshUI
    .

    (((((((((((((((((((((((((((( Autostart Punkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
    .
    .
    REGEDIT4
    *Hinweis* leere Eintrage & legitime Standardeintrage werden nicht angezeigt.

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BA7CB974-956C-456A-BB82-BEEC3B5E1750}]
    C:\WINDOWS\system32\urqOHWPG.dll

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DAEMON Tools Pro Agent"="C:\Programme\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 15:08 136136]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:57 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SunJavaUpdateSched"="C:\Programme\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
    "Launch LCDMon"="C:\Programme\Gemeinsame Dateien\Logitech\LCD Manager\lcdmon.exe" [2007-04-26 17:54 774168]
    "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 16:32 56080 C:\WINDOWS\KHALMNPR.Exe]
    "VolPanel"="C:\Programme\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" [2006-07-13 15:11 122880]
    "AudioDrvEmulator"="C:\Programme\Creative\Shared Files\Module Loader\DLLML.exe" [2005-11-04 19:07 49152]
    "egui"="C:\Programme\ESET\ESET Smart Security\egui.exe" [2007-12-21 09:21 1443072]
    "CTHelper"="CTHELPER.EXE" [2008-02-20 21:58 19456 C:\WINDOWS\system32\CtHelper.exe]
    "ati2sgav"="C:\WINDOWS\system32\ati2sgav.exe" [2008-04-08 11:50 206191]
    "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-03-24 19:52 13524992]
    "nwiz"="nwiz.exe" [2008-03-24 19:52 1626112 C:\WINDOWS\system32\nwiz.exe]
    "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-03-24 19:52 86016]
    "NBKeyScan"="C:\Programme\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [ ]
    "BM1f718f8f"="C:\WINDOWS\system32\iaecjrpf.dll" [ ]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "NoSMHelp"= 1 (0x1)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcBrRLf]
    efcBrRLf.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
    @=""

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
    --a------ 2008-03-07 15:26 89024 C:\Programme\SlySoft\AnyDVD\AnyDVD.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeviceDiscovery]
    --a------ 2003-05-21 19:37 229437 C:\Programme\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
    --a------ 2003-06-25 12:24 49152 C:\Programme\Hewlett-Packard\HP Software Update\HPWuSchd.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
    --a------ 2003-06-26 14:17 188416 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
    --a------ 2007-05-11 02:08 2512392 C:\WINDOWS\system32\oodtray.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
    "AlcoholAutomount"="C:\Programme\Alcohol Soft\Alcohol 120\axcmd.exe" /automount

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "QuickTime Task"="C:\Programme\QuickTime\qttask.exe" -atboottime
    "UpdReg"=C:\WINDOWS\UpdReg.EXE
    "NeroFilterCheck"=C:\Programme\Gemeinsame Dateien\Nero\Lib\NeroCheck.exe
    "Adobe Reader Speed Launcher"="C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    "CTxfiHlp"=CTXFIHLP.EXE

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "C:\\Programme\\Bonjour\\mDNSResponder.exe"=
    "C:\\Programme\\uTorrent\\uTorrent.exe"=
    "D:\\Pro Evolution Soccer 2008\\PES2008.exe"=
    "C:\\Programme\\ICQLite\\ICQLite.exe"=

    R2 CTAudSvcService;Creative Audio Service;C:\Programme\Creative\Shared Files\CTAudSvc.exe [2008-03-07 20:24]
    R2 LxrSII1d;Secure II Driver;C:\WINDOWS\system32\Drivers\LxrSII1d.sys [2006-12-14 10:37]
    R2 NMSAccessU;NMSAccessU;C:\Programme\CDBurnerXP\NMSAccessU.exe [2007-10-12 09:34]
    R2 UxTuneUp;TuneUp Designerweiterung;C:\WINDOWS\System32\svchost.exe [2004-08-04 00:58]
    R3 ha20x2k;Creative 20X HAL Driver;C:\WINDOWS\system32\drivers\ha20x2k.sys [2008-02-25 10:44]
    S3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;C:\WINDOWS\system32\DRIVERS\RTL8187.sys [2006-06-16 09:30]
    S3 TuneUp.Defrag;TuneUp Drive Defrag-Dienst;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-04-14 16:03]

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
    UxTuneUp

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{25584aea-0633-11dd-9107-0018f3645f89}]
    \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL DVR/AutoRun.exe start.exe


    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B9482BB3-D290-B4EC-C404-A72331581690}]
    C:\WINDOWS\system32\winamp.exe
    .
    Inhalt des "geplante Tasks" Ordners
    "2008-04-18 08:36:38 C:\WINDOWS\Tasks\1-Click Maintenance.job"
    - C:\Programme\TuneUp Utilities 2008\OneClickStarter.exe
    .
    **************************************************************************

    catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-04-18 10:36:54
    Windows 5.1.2600 Service Pack 2 NTFS

    Scanne versteckte Prozesse...

    Scanne versteckte Autostart Eintr„ge...

    Scanne versteckte Dateien...


    C:\WINDOWS\TEMP\u5jg9yoj.TMP

    Scan erfolgreich abgeschlossen
    versteckte Dateien: 1

    **************************************************************************
    .
    ------------------------ Other Running Processes ------------------------
    .
    C:\Programme\Bonjour\mDNSResponder.exe
    C:\Programme\Eset\ESET Smart Security\ekrn.exe
    C:\WINDOWS\system32\LxrSII1s.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\oodag.exe
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\WINDOWS\system32\PnkBstrB.exe
    C:\Programme\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    C:\WINDOWS\system32\CTxfispi.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Programme\Gemeinsame Dateien\Logitech\LCD Manager\Applets\LCDClock.exe
    C:\Programme\Gemeinsame Dateien\Logitech\LCD Manager\Applets\LCDMedia.exe
    C:\Programme\Logitech\SetPoint\SetPoint.exe
    C:\Programme\Internet Explorer\iexplore.exe
    C:\Programme\Gemeinsame Dateien\Logitech\KhalShared\KHALMNPR.exe
    .
    **************************************************************************
    .
    Zeit der Fertigstellung: 2008-04-18 10:38:47 - machine was rebooted [oWn4g3]
    ComboFix-quarantined-files.txt 2008-04-18 08:38:38

    10 Verzeichnis(se), 5,669,212,160 Bytes frei
    12 Verzeichnis(se), 5,613,842,432 Bytes frei


    Hope that it was the right decision and I hope that you can help me.
    Thanks in advance

  6. #6
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi

    Upload following files to http://virusscan.jotti.org and post back the results:
    C:\WINDOWS\UnGins.exe
    C:\xdfe52.dll
    C:\atm.dll
    C:\UNACE.dll



    Open notepad and copy/paste the text in the quotebox below into it:

    Code:
    File::
    C:\WINDOWS\system32\tpjaohmc.ini
    C:\WINDOWS\system32\hsaodgyr.ini
    C:\WINDOWS\system32\urqOHWPG.dll_old
    C:\WINDOWS\system32\tflvpiln.ini
    C:\WINDOWS\BM1f718f8f.xml
    C:\WINDOWS\UnGins.exe
    C:\WINDOWS\system32\winamp.exe
    
    Registry::
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BA7CB974-956C-456A-BB82-BEEC3B5E1750}]
    
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "BM1f718f8f"=-
    
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcBrRLf]
    
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{25584aea-0633-11dd-9107-0018f3645f89}]
    
    [-HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B9482BB3-D290-B4EC-C404-A72331581690}]

    Save this as
    CFScript




    Refering to the picture above, drag CFScript into ComboFix.exe
    Then post the resultant log.


    Combofix should never take more that 20 minutes including the reboot if malware is detected.
    If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
    If that happened we want to know, and also what process you had to end.


    Download ATF (Atribune Temp File) Cleaner© by Atribune to your desktop.

    Double-click ATF Cleaner.exe to open it

    Under Main choose:
    Windows Temp
    Current User Temp
    All Users Temp
    Cookies
    Temporary Internet Files
    Prefetch
    Java Cache

    *The other boxes are optional*
    Then click the Empty Selected button.

    If you use Firefox:
    Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

    If you use Opera:
    Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

    Click Exit on the Main menu to close the program.


    Run Kaspersky online scanner and post back its report & a fresh hjt log (without forgetting ComboFix resultant log meantioned above).
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  7. #7
    Junior Member
    Join Date
    Apr 2008
    Posts
    12

    Default

    Thanks for your help, I guess there is light at the end of the tunnel :D

    File: UnGins.exe
    Status: OK
    MD5: d6669c265d4280b3f149fae882d634a5
    Packers detected: -
    Bit9 reports: No threat detected (more info)

    --------------
    File: xdfe52.dll
    Status: INFECTED/MALWARE
    MD5: 89b5b81046a34f27aefd9e827c669d46
    Packers detected: -
    Bit9 reports: High threat detected (more info)

    ClamAV Found Trojan.Packed-4
    Sophos Antivirus Found Mal/Packer

    --------------

    File: atm.dll
    Status: OK
    MD5: 142aea530128844fef12d8c9ff1a491c
    Packers detected: -
    Bit9 reports: No threat detected (more info)

    --------------

    File: UNACE.dll
    Status: OK
    MD5: c7fc09f6c3650331619f553538e3a7c3
    Packers detected: PE_PATCH
    Bit9 reports: No threat detected (more info)


    I will now start Combofix with CFScript.txt

  8. #8
    Junior Member
    Join Date
    Apr 2008
    Posts
    12

    Default New Combofix Log

    ComboFix 08-04-16.5 - oWn4g3 2008-04-19 23:35:08.2 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1031.18.1523 [GMT 2:00]
    ausgeführt von:: C:\Dokumente und Einstellungen\oWn4g3\Desktop\ComboFix.exe
    Command switches used :: C:\Dokumente und Einstellungen\oWn4g3\Desktop\CFScript.txt
    * Neuer Wiederherstellungspunkt wurde erstellt
    * Resident AV is active


    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .

    ((((((((((((((((((((((( Dateien erstellt von 2008-03-19 bis 2008-04-19 ))))))))))))))))))))))))))))))
    .

    2008-04-17 22:50 . 2008-04-18 10:10 <DIR> d-------- C:\Programme\Hamachi
    2008-04-17 19:15 . 2008-04-17 19:15 <DIR> d-------- C:\Programme\Pivot Stickfigure Animator
    2008-04-16 14:45 . 2008-04-19 23:03 <DIR> d-------- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TrackMania
    2008-04-16 10:15 . 2008-04-16 10:15 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
    2008-04-16 10:15 . 2008-04-16 10:15 <DIR> d-------- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Kaspersky Lab
    2008-04-16 09:56 . 2008-04-16 09:56 <DIR> d-------- C:\Programme\Trend Micro
    2008-04-16 09:26 . 2008-04-17 09:26 414 ---hs---- C:\WINDOWS\system32\tpjaohmc.ini
    2008-04-15 16:30 . 2008-04-15 16:30 <DIR> d-------- C:\WINDOWS\nview
    2008-04-15 16:30 . 2008-04-15 16:30 <DIR> d-------- C:\WINDOWS\nvidia icons
    2008-04-15 16:30 . 2008-03-24 11:27 442,368 --a------ C:\WINDOWS\system32\NVUNINST.EXE
    2008-04-15 16:30 . 2008-03-24 19:52 442,368 --a------ C:\WINDOWS\system32\nvudisp.exe
    2008-04-15 16:30 . 2008-04-19 22:57 175,605 --a------ C:\WINDOWS\system32\nvapps.xml
    2008-04-15 16:30 . 2008-03-24 19:52 17,937 --a------ C:\WINDOWS\system32\nvdisp.nvu
    2008-04-15 16:29 . 2008-04-15 16:29 <DIR> d-------- C:\NVIDIA
    2008-04-15 14:56 . 2008-04-15 21:09 594 ---hs---- C:\WINDOWS\system32\hsaodgyr.ini
    2008-04-15 14:47 . 2008-04-15 14:47 272,384 --------- C:\WINDOWS\system32\urqOHWPG.dll_old
    2008-04-14 19:48 . 2008-04-15 14:42 <DIR> d-------- C:\Programme\tempa
    2008-04-14 19:48 . 2008-04-08 11:50 206,191 --a------ C:\WINDOWS\system32\ati2sgav.exe
    2008-04-14 16:07 . 2008-04-15 20:37 559 --a------ C:\WINDOWS\wininit.ini
    2008-04-14 16:03 . 2008-04-14 16:03 307,968 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
    2008-04-14 16:02 . 2008-02-27 13:15 28,416 --a------ C:\WINDOWS\system32\uxtuneup.dll
    2008-04-14 07:20 . 2008-04-14 16:26 354 ---hs---- C:\WINDOWS\system32\tflvpiln.ini
    2008-04-14 07:12 . 2008-04-17 08:54 101,091 --a------ C:\WINDOWS\BM1f718f8f.xml
    2008-04-13 14:15 . 2008-04-13 14:16 <DIR> d-------- C:\WINDOWS\Sins Bonuspack
    2008-04-11 21:36 . 2008-04-13 14:49 54,156 --ah----- C:\WINDOWS\QTFont.qfn
    2008-04-11 21:36 . 2008-04-11 21:36 1,409 --a------ C:\WINDOWS\QTFont.for
    2008-04-11 17:07 . 2008-04-11 17:07 <DIR> d-------- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Ubisoft
    2008-04-11 16:54 . 2008-04-14 19:48 441,652 --a------ C:\WINDOWS\system32\winamp.exe
    2008-04-09 14:33 . 2008-04-09 14:33 <DIR> d-------- C:\WINDOWS\.jagex_cache_32
    2008-04-06 12:39 . 2000-07-08 15:06 87,040 --a------ C:\WINDOWS\UnGins.exe
    2008-04-06 12:34 . 2008-04-06 12:34 457,728 --a------ C:\xdfe52.dll
    2008-04-06 12:34 . 2008-04-06 12:34 69,120 --a------ C:\atm.dll
    2008-04-06 12:34 . 2008-04-06 12:34 45,056 --a------ C:\UNACE.dll
    2008-04-03 01:26 . 2008-04-03 01:26 41,296 --a------ C:\WINDOWS\system32\xfcodec.dll
    2008-03-27 17:17 . 2008-03-27 21:21 <DIR> d-------- C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Command & Conquer 3 Kanes Rache
    2008-03-27 00:04 . 2008-04-05 01:41 <DIR> d---s---- C:\Programme\HLSW
    2008-03-27 00:04 . 2008-04-05 02:52 <DIR> d-------- C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\HLSW
    2008-03-26 18:26 . 2008-03-26 18:26 <DIR> d-------- C:\Programme\OpenOffice.org 2.4
    2008-03-25 15:38 . 2008-03-25 15:38 34,198 --a------ C:\Star Wars Battlefront II .mds
    2008-03-24 16:25 . 2008-03-25 15:42 3,914,283,008 --a------ C:\Star Wars Battlefront II .mdf
    2008-03-23 18:05 . 2008-03-23 18:05 122 --a------ C:\WINDOWS\WA.INI
    2008-03-23 18:04 . 2008-03-23 18:04 1,559,605 --a------ C:\WINDOWS\WANEUninstaller.exe
    2008-03-23 15:36 . 2008-03-23 15:36 <DIR> d-------- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Age of Empires 3
    2008-03-20 18:06 . 2008-03-20 18:06 <DIR> d-------- C:\WINDOWS\PreviewSoft
    2008-03-20 18:06 . 2008-03-20 18:06 <DIR> d-------- C:\WINDOWS\Noslip
    2008-03-20 18:06 . 2008-03-20 18:06 <DIR> d-------- C:\Programme\Ulead GIF Animator 5
    2008-03-20 18:06 . 1999-10-15 13:50 1,056,768 --a------ C:\WINDOWS\system32\ROBOEX32.DLL
    2008-03-20 18:06 . 1999-01-28 16:44 49,152 --a------ C:\WINDOWS\system32\INETWH32.dll
    2008-03-20 18:06 . 2008-03-20 18:06 4,808 --a------ C:\WINDOWS\system32\gaeffect.sti
    2008-03-20 18:06 . 2008-03-20 18:06 3,176 --a------ C:\WINDOWS\system32\gafilter.sti
    2008-03-20 18:06 . 2008-03-20 20:50 550 --ah----- C:\os466477.bin
    2008-03-20 18:06 . 2008-03-20 20:50 449 --ah----- C:\WINDOWS\system32\ws344069.ocx
    2008-03-20 18:06 . 2008-03-20 20:50 312 --a------ C:\WINDOWS\ULEAD32.INI
    2008-03-19 16:18 . 2008-03-19 16:18 <DIR> d-------- C:\Programme\Latein-Wörterbuch

    .
    (((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-04-19 16:01 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Xfire
    2008-04-19 14:44 --------- d-----w C:\Programme\BOINC
    2008-04-19 14:10 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\teamspeak2
    2008-04-19 10:44 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\OpenOffice.org2
    2008-04-19 10:18 --------- d-----w C:\Programme\Mozilla Thunderbird
    2008-04-19 09:31 --------- d-s---w C:\Programme\Xfire
    2008-04-18 14:14 --------- d-----w C:\Programme\PowerArchiver
    2008-04-17 22:41 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Hamachi
    2008-04-17 20:52 16,224 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys
    2008-04-17 17:17 --------- d-----w C:\Programme\Trillian
    2008-04-17 07:42 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
    2008-04-16 12:55 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Skype
    2008-04-16 11:08 --------- d-----w C:\Programme\Gemeinsame Dateien\Wise Installation Wizard
    2008-04-16 08:13 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\uTorrent
    2008-04-15 19:27 --------- d-----w C:\Programme\mIRC
    2008-04-15 19:27 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\mIRC
    2008-04-15 17:11 --------- d-----w C:\Programme\Gemeinsame Dateien\Nero
    2008-04-14 14:03 --------- d-----w C:\Programme\TuneUp Utilities 2008
    2008-04-13 12:07 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Free Download Manager
    2008-04-11 15:07 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
    2008-04-11 15:07 22,328 ----a-w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\PnkBstrK.sys
    2008-04-11 15:06 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
    2008-04-11 15:03 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
    2008-04-11 15:03 2,337,865 ----a-w C:\WINDOWS\system32\pbsvc.exe
    2008-04-11 14:55 --------- d--h--w C:\Programme\InstallShield Installation Information
    2008-04-10 16:10 --------- d-----w C:\Programme\SpeedFan
    2008-03-31 16:16 --------- d-----w C:\Programme\Winamp
    2008-03-31 16:16 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Winamp
    2008-03-17 16:35 --------- d-----w C:\Programme\Java
    2008-03-16 12:50 --------- d-----w C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Creative
    2008-03-16 12:41 413,696 ----a-w C:\WINDOWS\system32\wrap_oal.dll
    2008-03-16 12:41 110,592 ----a-w C:\WINDOWS\system32\OpenAL32.dll
    2008-03-16 12:40 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Creative
    2008-03-14 09:38 --------- d-----w C:\Programme\Audacity
    2008-03-09 19:02 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Media Player Classic
    2008-03-09 19:01 --------- d-----w C:\Programme\XP Codec Pack
    2008-03-07 13:24 97,216 ----a-w C:\WINDOWS\system32\drivers\AnyDVD.sys
    2008-03-06 15:29 962,560 ----a-w C:\WINDOWS\system32\VSFilter.dll
    2008-03-04 17:12 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
    2008-03-02 19:27 --------- d---a-w C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP
    2008-03-02 10:12 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\dvdcss
    2008-02-29 09:21 --------- d-----w C:\Programme\AGEIA Technologies
    2008-02-25 19:32 --------- d-----w C:\Programme\DivX
    2008-02-25 08:45 189,464 ----a-w C:\WINDOWS\system32\drivers\haP17v2k.sys
    2008-02-25 08:45 15,896 ----a-w C:\WINDOWS\system32\drivers\pfmodnt.sys
    2008-02-25 08:44 92,696 ----a-w C:\WINDOWS\system32\drivers\emupia2k.sys
    2008-02-25 08:44 797,720 ----a-w C:\WINDOWS\system32\drivers\ha10kx2k.sys
    2008-02-25 08:44 162,840 ----a-w C:\WINDOWS\system32\drivers\haP16v2k.sys
    2008-02-25 08:44 157,208 ----a-w C:\WINDOWS\system32\drivers\ctsfm2k.sys
    2008-02-25 08:44 14,360 ----a-w C:\WINDOWS\system32\drivers\ctprxy2k.sys
    2008-02-25 08:44 1,172,504 ----a-w C:\WINDOWS\system32\drivers\ha20x2k.sys
    2008-02-25 08:43 524,312 ----a-w C:\WINDOWS\system32\drivers\ctaud2k.sys
    2008-02-25 08:43 511,000 ----a-w C:\WINDOWS\system32\drivers\ctac32k.sys
    2008-02-25 08:43 346,856 ----a-w C:\WINDOWS\system32\drivers\ctdvda2k.sys
    2008-02-25 08:43 18,840 ----a-w C:\WINDOWS\system32\drivers\CTGAME.SYS
    2008-02-25 08:43 127,000 ----a-w C:\WINDOWS\system32\drivers\ctoss2k.sys
    2008-02-25 08:43 1,372,568 ----a-w C:\WINDOWS\system32\drivers\CTMMFILT.SYS
    2008-02-25 08:43 1,366,424 ----a-w C:\WINDOWS\system32\drivers\CT0531FL.SYS
    2008-02-25 08:41 72,728 ----a-w C:\WINDOWS\system32\CTHWIUT.DLL
    2008-02-25 08:41 566,296 ----a-w C:\WINDOWS\system32\CTSBLFX.DLL
    2008-02-25 08:41 329,240 ----a-w C:\WINDOWS\system32\CTEDSPSY.DLL
    2008-02-25 08:41 286,232 ----a-w C:\WINDOWS\system32\CTEDSPFX.DLL
    2008-02-25 08:41 174,104 ----a-w C:\WINDOWS\system32\CTEAPSFX.DLL
    2008-02-25 08:41 170,520 ----a-w C:\WINDOWS\system32\CT20XUT.DLL
    2008-02-25 08:41 134,680 ----a-w C:\WINDOWS\system32\CTEDSPIO.DLL
    2008-02-25 08:41 100,888 ----a-w C:\WINDOWS\system32\CTERFXFX.DLL
    2008-02-25 08:41 1,323,544 ----a-w C:\WINDOWS\system32\CTEXFIFX.DLL
    2008-02-25 08:40 98,328 ----a-w C:\WINDOWS\system32\COMMONFX.DLL
    2008-02-25 08:40 551,960 ----a-w C:\WINDOWS\system32\CTAUDFX.DLL
    2008-02-21 02:05 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
    2008-02-21 02:05 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
    2008-02-21 02:05 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
    2008-02-21 02:05 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
    2008-02-21 02:04 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
    2008-02-21 02:04 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
    2008-02-21 02:04 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
    2008-02-21 02:04 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
    2008-02-21 02:04 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
    2008-02-21 02:04 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
    2008-02-21 02:04 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
    2008-02-21 02:04 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
    2008-02-21 02:04 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
    2008-02-21 02:04 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
    2008-02-21 02:04 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
    2008-02-21 02:04 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
    2008-02-21 02:03 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
    2008-02-21 02:03 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
    2008-02-20 20:00 43,520 ----a-w C:\WINDOWS\system32\CTBurst.dll
    2008-02-20 19:59 86,016 ----a-w C:\WINDOWS\system32\ctcoinst.dll
    2008-02-20 19:59 34,816 ----a-w C:\WINDOWS\system32\a3d.dll
    2008-02-20 19:59 27,648 ----a-w C:\WINDOWS\system32\ac3api.dll
    2008-02-20 19:59 163,840 ----a-w C:\WINDOWS\system32\ctdvinst.dll
    2008-02-20 19:55 969,216 ----a-w C:\WINDOWS\system32\CTxfispi.exe
    2008-02-20 19:55 43,520 ----a-w C:\WINDOWS\system32\Ctxfireg.exe
    2008-02-20 19:55 10,752 ----a-w C:\WINDOWS\system32\Ct20xspi.dll
    2008-02-20 19:49 110,080 ----a-w C:\WINDOWS\system32\ctemupia.dll
    2008-02-20 19:47 49,152 ----a-w C:\WINDOWS\system32\ctdproxy.dll
    2008-02-20 19:47 46,592 ----a-w C:\WINDOWS\system32\ctasio.dll
    2008-02-20 19:47 174,592 ----a-w C:\WINDOWS\system32\ct_oal.dll
    2008-02-20 19:47 17,920 ----a-w C:\WINDOWS\system32\ctedasio.dll
    .

    ((((((((((((((((((((((((((((( snapshot@2008-04-18_10.38.32.46 )))))))))))))))))))))))))))))))))))))))))
    .
    - 2008-04-18 08:34:41 2,048 --s-a-w C:\WINDOWS\bootstat.dat
    + 2008-04-19 20:57:27 2,048 --s-a-w C:\WINDOWS\bootstat.dat
    - 2008-03-30 09:24:10 70,778 ----a-w C:\WINDOWS\system32\perfc007.dat
    + 2008-04-18 08:39:15 70,778 ----a-w C:\WINDOWS\system32\perfc007.dat
    - 2008-03-30 09:24:10 58,732 ----a-w C:\WINDOWS\system32\perfc009.dat
    + 2008-04-18 08:39:15 58,732 ----a-w C:\WINDOWS\system32\perfc009.dat
    - 2008-03-30 09:24:10 405,448 ----a-w C:\WINDOWS\system32\perfh007.dat
    + 2008-04-18 08:39:15 405,448 ----a-w C:\WINDOWS\system32\perfh007.dat
    - 2008-03-30 09:24:10 392,432 ----a-w C:\WINDOWS\system32\perfh009.dat
    + 2008-04-18 08:39:15 392,432 ----a-w C:\WINDOWS\system32\perfh009.dat
    .
    (((((((((((((((((((((((((((( Autostart Punkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
    .
    .
    REGEDIT4
    *Hinweis* leere Eintrage & legitime Standardeintrage werden nicht angezeigt.

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BA7CB974-956C-456A-BB82-BEEC3B5E1750}]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DAEMON Tools Pro Agent"="C:\Programme\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 15:08 136136]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:57 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SunJavaUpdateSched"="C:\Programme\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
    "Launch LCDMon"="C:\Programme\Gemeinsame Dateien\Logitech\LCD Manager\lcdmon.exe" [2007-04-26 17:54 774168]
    "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 16:32 56080 C:\WINDOWS\KHALMNPR.Exe]
    "VolPanel"="C:\Programme\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" [2006-07-13 15:11 122880]
    "AudioDrvEmulator"="C:\Programme\Creative\Shared Files\Module Loader\DLLML.exe" [2005-11-04 19:07 49152]
    "egui"="C:\Programme\ESET\ESET Smart Security\egui.exe" [2007-12-21 09:21 1443072]
    "CTHelper"="CTHELPER.EXE" [2008-02-20 21:58 19456 C:\WINDOWS\system32\CtHelper.exe]
    "ati2sgav"="C:\WINDOWS\system32\ati2sgav.exe" [2008-04-08 11:50 206191]
    "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-03-24 19:52 13524992]
    "nwiz"="nwiz.exe" [2008-03-24 19:52 1626112 C:\WINDOWS\system32\nwiz.exe]
    "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-03-24 19:52 86016]
    "BM1f718f8f"="C:\WINDOWS\system32\iaecjrpf.dll" [ ]

    C:\Dokumente und Einstellungen\All Users\Startmen\Programme\Autostart\
    Logitech SetPoint.lnk - C:\Programme\Logitech\SetPoint\SetPoint.exe [2007-10-28 20:01:39 692224]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "NoSMHelp"= 1 (0x1)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcBrRLf]
    efcBrRLf.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
    @=""

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
    --a------ 2008-03-07 15:26 89024 C:\Programme\SlySoft\AnyDVD\AnyDVD.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeviceDiscovery]
    --a------ 2003-05-21 19:37 229437 C:\Programme\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
    --a------ 2003-06-25 12:24 49152 C:\Programme\Hewlett-Packard\HP Software Update\HPWuSchd.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
    --a------ 2003-06-26 14:17 188416 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
    --a------ 2007-05-11 02:08 2512392 C:\WINDOWS\system32\oodtray.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "wscsvc"=2 (0x2)
    "LxrSII1s"=2 (0x2)
    "wuauserv"=2 (0x2)

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
    "AlcoholAutomount"="C:\Programme\Alcohol Soft\Alcohol 120\axcmd.exe" /automount

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "QuickTime Task"="C:\Programme\QuickTime\qttask.exe" -atboottime
    "UpdReg"=C:\WINDOWS\UpdReg.EXE
    "Adobe Reader Speed Launcher"="C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    "CTxfiHlp"=CTXFIHLP.EXE

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "C:\\Programme\\Bonjour\\mDNSResponder.exe"=
    "C:\\Programme\\uTorrent\\uTorrent.exe"=
    "D:\\Pro Evolution Soccer 2008\\PES2008.exe"=
    "C:\\Programme\\ICQLite\\ICQLite.exe"=

    R2 CTAudSvcService;Creative Audio Service;C:\Programme\Creative\Shared Files\CTAudSvc.exe [2008-03-07 20:24]
    R2 LxrSII1d;Secure II Driver;C:\WINDOWS\system32\Drivers\LxrSII1d.sys [2006-12-14 10:37]
    R2 NMSAccessU;NMSAccessU;C:\Programme\CDBurnerXP\NMSAccessU.exe [2007-10-12 09:34]
    R2 UxTuneUp;TuneUp Designerweiterung;C:\WINDOWS\System32\svchost.exe [2004-08-04 00:58]
    R3 ha20x2k;Creative 20X HAL Driver;C:\WINDOWS\system32\drivers\ha20x2k.sys [2008-02-25 10:44]
    S3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;C:\WINDOWS\system32\DRIVERS\RTL8187.sys [2006-06-16 09:30]
    S3 TuneUp.Defrag;TuneUp Drive Defrag-Dienst;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-04-14 16:03]

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
    UxTuneUp

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{25584aea-0633-11dd-9107-0018f3645f89}]
    \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL DVR/AutoRun.exe start.exe

    *Newly Created Service* - CATCHME

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B9482BB3-D290-B4EC-C404-A72331581690}]
    C:\WINDOWS\system32\winamp.exe
    .
    Inhalt des "geplante Tasks" Ordners
    "2008-04-19 21:00:00 C:\WINDOWS\Tasks\1-Click Maintenance.job"
    - C:\Programme\TuneUp Utilities 2008\OneClickStarter.exe
    .
    **************************************************************************

    catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-04-19 23:36:21
    Windows 5.1.2600 Service Pack 2 NTFS

    Scanne versteckte Prozesse...

    Scanne versteckte Autostart Einträge...

    Scanne versteckte Dateien...

    Scan erfolgreich abgeschlossen
    versteckte Dateien: 0

    **************************************************************************
    .
    Zeit der Fertigstellung: 2008-04-19 23:37:01
    ComboFix-quarantined-files.txt 2008-04-19 21:36:37
    ComboFix2.txt 2008-04-18 08:38:47

    10 Verzeichnis(se), 5,477,318,656 Bytes frei
    12 Verzeichnis(se), 5,493,096,448 Bytes frei

  9. #9
    Junior Member
    Join Date
    Apr 2008
    Posts
    12

    Default New Kaspersky Log

    -------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER REPORT
    Sunday, April 20, 2008 12:03:49 AM
    Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
    Kaspersky Online Scanner version: 5.0.98.0
    Kaspersky Anti-Virus database last update: 19/04/2008
    Kaspersky Anti-Virus database records: 715802
    -------------------------------------------------------------------------------

    Scan Settings:
    Scan using the following antivirus database: extended
    Scan Archives: true
    Scan Mail Bases: true

    Scan Target - Folders:
    C:\

    Scan Statistics:
    Total number of scanned objects: 63394
    Number of viruses found: 5
    Number of infected objects: 6
    Number of suspicious objects: 0
    Duration of the scan process: 00:18:06

    Infected Object Name / Virus Name / Last Action
    C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ESET\ESET Smart Security\Charon\CACHE.NDB Object is locked skipped
    C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ESET\ESET Smart Security\Logs\epfwlog.dat Object is locked skipped
    C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ESET\ESET Smart Security\Logs\virlog.dat Object is locked skipped
    C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ESET\ESET Smart Security\Logs\warnlog.dat Object is locked skipped
    C:\Dokumente und Einstellungen\LocalService\Cookies\index.dat Object is locked skipped
    C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Verlauf\History.IE5\index.dat Object is locked skipped
    C:\Dokumente und Einstellungen\LocalService\NTUSER.DAT Object is locked skipped
    C:\Dokumente und Einstellungen\LocalService\ntuser.dat.LOG Object is locked skipped
    C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Dokumente und Einstellungen\NetworkService\NTUSER.DAT Object is locked skipped
    C:\Dokumente und Einstellungen\NetworkService\ntuser.dat.LOG Object is locked skipped
    C:\Dokumente und Einstellungen\oWn4g3\Cookies\index.dat Object is locked skipped
    C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Anwendungsdaten\Microsoft\Feeds Cache\index.dat Object is locked skipped
    C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
    C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Verlauf\History.IE5\index.dat Object is locked skipped
    C:\Dokumente und Einstellungen\oWn4g3\Lokale Einstellungen\Verlauf\History.IE5\MSHist012008041920080420\index.dat Object is locked skipped
    C:\Dokumente und Einstellungen\oWn4g3\NTUSER.DAT Object is locked skipped
    C:\Dokumente und Einstellungen\oWn4g3\ntuser.dat.LOG Object is locked skipped
    C:\Programme\Alcohol Soft\Alcohol 120\StarWind\logs\sw_ae-20080419-225745.log Object is locked skipped
    C:\Programme\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.631 skipped
    C:\QooBox\Quarantine\C\WINDOWS\system32\hjrpanhj.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.pim skipped
    C:\QooBox\Quarantine\C\WINDOWS\system32\inomkxmb.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.pik skipped
    C:\QooBox\Quarantine\C\WINDOWS\system32\ltrfsmvk.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.pjx skipped
    C:\QooBox\Quarantine\catchme2008-04-18_103304,32.zip/ddcCVPif.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.pki skipped
    C:\QooBox\Quarantine\catchme2008-04-18_103304,32.zip ZIP: infected - 1 skipped
    C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
    C:\System Volume Information\_restore{3574B6F9-47AC-4E3F-9F4E-69795126CC8B}\RP2\change.log Object is locked skipped
    C:\WINDOWS\CSC\00000001 Object is locked skipped
    C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
    C:\WINDOWS\S96B3E77A.tmp Object is locked skipped
    C:\WINDOWS\SchedLgU.Txt Object is locked skipped
    C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
    C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
    C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\default Object is locked skipped
    C:\WINDOWS\system32\config\default.LOG Object is locked skipped
    C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
    C:\WINDOWS\system32\config\SAM Object is locked skipped
    C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\SECURITY Object is locked skipped
    C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
    C:\WINDOWS\system32\config\software Object is locked skipped
    C:\WINDOWS\system32\config\software.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\system Object is locked skipped
    C:\WINDOWS\system32\config\system.LOG Object is locked skipped
    C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
    C:\WINDOWS\system32\h323log.txt Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

    Scan process completed.



    Seems like something is still infected.

  10. #10
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi

    Yes, let's take another run and remove those 4 files you got scanned. I'm not convinced that those other 3 are clean either.

    This time let's do the run in safe mode since it seems resident protection prevents ComboFix from operating correctly. Before that save/print these instructions since you won't be able to access them while in safe mode.

    Reboot into safe mode.

    While in safe mode open notepad and copy/paste the text in the quotebox below into it:

    Code:
    KILLALL::
    
    File::
    C:\WINDOWS\system32\tpjaohmc.ini
    C:\WINDOWS\system32\hsaodgyr.ini
    C:\WINDOWS\system32\urqOHWPG.dll_old
    C:\WINDOWS\system32\ati2sgav.exe
    C:\WINDOWS\system32\tflvpiln.ini
    C:\WINDOWS\BM1f718f8f.xml
    C:\WINDOWS\system32\winamp.exe	
    C:\WINDOWS\UnGins.exe
    C:\xdfe52.dll
    C:\atm.dll
    C:\UNACE.dll
    
    Folder::
    C:\Programme\tempa
    
    Registry::
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BA7CB974-956C-456A-BB82-BEEC3B5E1750}]
    
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ati2sgav"=-
    "BM1f718f8f"=-
    
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcBrRLf]
    
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{25584aea-0633-11dd-9107-0018f3645f89}]
    
    [-HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B9482BB3-D290-B4EC-C404-A72331581690}]

    Save this as
    CFScript




    Refering to the picture above, drag CFScript into ComboFix.exe
    Then reboot back into normal mode and post the resultant log (c:\ComboFix\ComboFix.txt contents) & a fresh hjt log.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •