Spybot S&D found Zlob.DNSChanger.
Fixes/delets it, yet it keeps popping back up after reboot.
Pareto's RegCure and XoftSpySE find a "problem", but then Window steps in, reports a problem, that the program has to be ended and a report to Window will be sent.
(Naturally Windows never got back to us upon receiving this report ...)
Anyways -
I went through some threads here and found a tip to download and run Fixwareout, reboot and post the report.
Hence here it is:
Username "Isolde" - 12.01.2008 10:09:17 [Fixwareout edited 9/01/2007]
~~~~~ Prerun check
HKLM\SOFTWARE\~\Winlogon\ "System"="kdbdv.exe"
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{A9F65E29-4B0E-4240-A503-65BAA3E0E07F}
"nameserver"="85.255.116.133,85.255.112.87" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{A9F65E29-4B0E-4240-A503-65BAA3E0E07F}
"DhcpNameServer"="85.255.116.133,85.255.112.87" <Value cleared.
Der DNS-Auflösungscache wurde geleert.
System was rebooted successfully.
~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
....
....
~~~~~ Misc files.
....
~~~~~ Checking for older varients.
....
~~~~~ Other
C:\WINDOWS\TEMP\kdbdv.ren 73818 13.06.2007
~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE"
"IgfxTray"="C:\\WINDOWS\\System32\\igfxtray.exe"
"SunJavaUpdateSched"="\"C:\\Programme\\Java\\jre1.6.0_03\\bin\\jusched.exe\""
"TkBellExe"="\"C:\\Programme\\Gemeinsame Dateien\\Real\\Update_OB\\realsched.exe\" -osboot"
"UnlockerAssistant"="\"C:\\Programme\\Unlocker\\UnlockerAssistant.exe\""
"Adobe Reader Speed Launcher"="\"C:\\Programme\\Adobe\\Reader 8.0\\Reader\\Reader_sl.exe\""
"Monitor"="C:\\WINDOWS\\PixArt\\PAC207\\Monitor.exe"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
....
Hosts file was reset, If you use a custom hosts file please replace it...
~~~~~ End report ~~~~~
Now what?
Thank you for your help, anyone.
Fixes/delets it, yet it keeps popping back up after reboot.
Pareto's RegCure and XoftSpySE find a "problem", but then Window steps in, reports a problem, that the program has to be ended and a report to Window will be sent.
(Naturally Windows never got back to us upon receiving this report ...)
Anyways -
I went through some threads here and found a tip to download and run Fixwareout, reboot and post the report.
Hence here it is:
Username "Isolde" - 12.01.2008 10:09:17 [Fixwareout edited 9/01/2007]
~~~~~ Prerun check
HKLM\SOFTWARE\~\Winlogon\ "System"="kdbdv.exe"
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{A9F65E29-4B0E-4240-A503-65BAA3E0E07F}
"nameserver"="85.255.116.133,85.255.112.87" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{A9F65E29-4B0E-4240-A503-65BAA3E0E07F}
"DhcpNameServer"="85.255.116.133,85.255.112.87" <Value cleared.
Der DNS-Auflösungscache wurde geleert.
System was rebooted successfully.
~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
....
....
~~~~~ Misc files.
....
~~~~~ Checking for older varients.
....
~~~~~ Other
C:\WINDOWS\TEMP\kdbdv.ren 73818 13.06.2007
~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE"
"IgfxTray"="C:\\WINDOWS\\System32\\igfxtray.exe"
"SunJavaUpdateSched"="\"C:\\Programme\\Java\\jre1.6.0_03\\bin\\jusched.exe\""
"TkBellExe"="\"C:\\Programme\\Gemeinsame Dateien\\Real\\Update_OB\\realsched.exe\" -osboot"
"UnlockerAssistant"="\"C:\\Programme\\Unlocker\\UnlockerAssistant.exe\""
"Adobe Reader Speed Launcher"="\"C:\\Programme\\Adobe\\Reader 8.0\\Reader\\Reader_sl.exe\""
"Monitor"="C:\\WINDOWS\\PixArt\\PAC207\\Monitor.exe"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
....
Hosts file was reset, If you use a custom hosts file please replace it...
~~~~~ End report ~~~~~
Now what?
Thank you for your help, anyone.