This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Exploit.Java.Agent.f and paretologic (continued I)

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I've caught one or more viruses, acting as browser-hijacker. The usual spyware (Spybot, Ad-Aware, Spyware-Blaster, Antivir) didn't detect it. Running an online-scan with Kaspersky online scanner showed as results: ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Tuesday, May 11, 2010 Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Monday, May 10, 2010 18:57:02 Records in database: 4091672 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ Scan statistics: Objects scanned: 109200 Threats found: 1 Infected objects found: 2 Suspicious objects found: 0 Scan duration: 02:41:04 File name / Threat / Threats count C:\Dokumente und Einstellungen\Ulrike Klöppel\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\45\352e636d-4eab7c81 Infected: Exploit.Java.Agent.f 1 C:\Dokumente und Einstellungen\Ulrike Klöppel\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\54\11c850f6-6e601624 Infected: Exploit.Java.Agent.f 1 Selected area has been scanned. ———————————————– After reading in your forum I don't dare to delete the files Exploit.Java.Agent.f just like this. What would you recommend? Also I found traces of paretologic on my computer that I was not aware of. I causes error alerts from windows. I traced it back to a file on c:\programme\gemeinsame Dateien\Paretologic\UUS2\UUS.dll. What would you advise to get rid of this problem? I post the results of scans that you request for initial contact in the next question form (also see attachment): Thank you for your help! Kind regards, Ulli

Attachments:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-05-11 16:03:12
Windows 5.1.2600 Service Pack 3
Running: cv1m97vh.exe; Driver: C:\DOKUME~1\ULRIKE~1\LOKALE~1\Temp\ugldapob.sys


—- System - GMER 1.0.15 —-

SSDT F7B887F6 ZwCreateKey
SSDT F7B887EC ZwCreateThread
SSDT F7B887FB ZwDeleteKey
SSDT F7B88805 ZwDeleteValueKey
SSDT F7B8880A ZwLoadKey
SSDT F7B887D8 ZwOpenProcess
SSDT F7B887DD ZwOpenThread
SSDT F7B88814 ZwReplaceKey
SSDT F7B8880F ZwRestoreKey
SSDT F7B88800 ZwSetValueKey

—- Kernel code sections - GMER 1.0.15 —-

.rsrc C:\WINDOWS\system32\drivers\shpf.sys entry point in ".rsrc" section [0xF7813014]

—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\System32\svchost.exe[1320] ntdll.dll!NtProtectVirtualMemory 7C91D6EE 5 Bytes JMP 007E000A
.text C:\WINDOWS\System32\svchost.exe[1320] ntdll.dll!NtWriteVirtualMemory 7C91DFAE 5 Bytes JMP 007F000A
.text C:\WINDOWS\System32\svchost.exe[1320] ntdll.dll!KiUserExceptionDispatcher 7C91E47C 5 Bytes JMP 007D000C
.text C:\WINDOWS\System32\svchost.exe[1320] USER32.dll!GetCursorPos 7E37974E 5 Bytes JMP 0273000A
.text C:\WINDOWS\System32\svchost.exe[1320] ole32.dll!CoCreateInstance 774D057E 5 Bytes JMP 0224000A
.text C:\WINDOWS\Explorer.EXE[1620] ntdll.dll!NtProtectVirtualMemory 7C91D6EE 5 Bytes JMP 00A1000A
.text C:\WINDOWS\Explorer.EXE[1620] ntdll.dll!NtWriteVirtualMemory 7C91DFAE 5 Bytes JMP 00AF000A
.text C:\WINDOWS\Explorer.EXE[1620] ntdll.dll!KiUserExceptionDispatcher 7C91E47C 5 Bytes JMP 00A0000C

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Tcp Lbd.sys (Boot Driver/Lavasoft AB)

Device -> \Driver\atapi \Device\Harddisk0\DR0 86E62EE4

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\system32\drivers\shpf.sys suspicious modification
File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification

—- EOF - GMER 1.0.15 —-

Attachments:

Hello ulli and welcome to WhatTheTech. I’ll be happy to look over your log and help you with your issues. It will be very helpful if you follow these guidelines:
  • Malware removal is a sometimes lengthy and tedious process. Please stick with the thread until I’ve given you the “All clear.” Absence of symptoms does not mean your machine is clean!
  • Please do not run any scans or install/uninstall any applications without being directed to do so.
  • Please follow my instructions carefully and in the order they are posted.
  • Any underlined text in my posts indicates a clickable link.
  • You should print any instructions I give you for ease of use and reference.
  • If you have any questions at all, please stop and ask before proceeding.
🖼Click to load external image (Posted Image) DDS should have produced two reports, DDS.txt and Attach.txt. I need to see the DDS.txt report. Run DDS again if you need to and post your DDS.txt log for me.
For some unknown reasons I can't send the whole content of dds.txt at once - I try now in pieces. that's the first one. DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 8:35:33,65 on 11.05.2010 Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_19 Microsoft Windows XP Home Edition 5.1.2600.3.1252.49.1031.18.1014.382 [GMT 1:00] AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7} FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup C:\Programme\Intel\Wireless\Bin\EvtEng.exe C:\Programme\Intel\Wireless\Bin\S24EvMon.exe svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Programme\Avira\AntiVir Desktop\sched.exe svchost.exe C:\Programme\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe C:\Programme\Avira\AntiVir Desktop\avguard.exe C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Programme\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\drivers\CDAC11BA.EXE C:\Programme\Avira\AntiVir Desktop\avshadow.exe C:\Programme\Intel\Wireless\Bin\RegSrvc.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Programme\Sony\VAIO Event Service\VESMgr.exe C:\Programme\Gemeinsame Dateien\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe C:\WINDOWS\system32\fxssvc.exe C:\Programme\Gemeinsame Dateien\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe C:\Programme\Gemeinsame Dateien\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe C:\Programme\Apoint\Apoint.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\system32\ICO.EXE C:\Programme\Intel\Wireless\Bin\EOUWiz.exe C:\Programme\Sony\VAIO Power Management\SPMgr.exe C:\Programme\Sony\ISB Utility\ISBMgr.exe C:\Programme\Logitech\iTouch\iTouch.exe C:\WINDOWS\Logi_MwX.Exe C:\Programme\Intel\Wireless\bin\ZCfgSvc.exe C:\Programme\Intel\Wireless\Bin\ifrmewrk.exe C:\Programme\Avira\AntiVir Desktop\avgnt.exe C:\Programme\UsbBoost\TurboHddUsb.exe C:\Programme\FreePDF_XP\fpassist.exe C:\Programme\Canon\MyPrinter\BJMyPrt.exe C:\Programme\ScanSoft\OmniPageSE4\OpwareSE4.exe C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtProc.exe C:\Programme\iTunes\iTunesHelper.exe C:\Programme\Apoint\Apntex.exe C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Programme\Intel\Wireless\Bin\Dot1XCfg.exe C:\WINDOWS\system32\ctfmon.exe C:\Programme\Adobe\Acrobat 6.0\Distillr\acrotray.exe C:\Programme\iPod\bin\iPodService.exe C:\WINDOWS\explorer.exe C:\Programme\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\Pelmiced.exe C:\Programme\Java\jre6\bin\java.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\wuauclt.exe C:\Dokumente und Einstellungen\Ulrike Klöppel\Desktop\dds.scr ============== Pseudo HJT Report ===============
here comes the second piece (I cannot even upload a whole section of the file!!) ============== Pseudo HJT Report =============== uStart Page = about:blank uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie mDefault_Page_URL = hxxp://www.club-vaio.com/de/ mDefault_Search_URL = hxxp://www.google.com/ie uInternet Connection Wizard,ShellNext = hxxp://www.club-vaio.com/de/ uInternet Settings,ProxyOverride = uInternet Settings,ProxyServer = http=127.0.0.1:5555 uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.google.com/ie BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\programme\adobe\acrobat 6.0\acrobat\activex\AcroIEHelper.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\programme\gemeinsame dateien\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\programme\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll BHO: PDF-XChange Viewer IE-Plugin: {c5d07eb6-bbce-4dae-acbb-d13a8d28cb1f} - c:\programme\pdf-xchange viewer\pdf-viewer\PDFXCviewIEPlugin.dll BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\progra~1\google~1\GoogleAFE.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\programme\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\programme\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\programme\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
ok, I could not attach the dds.txt but after converting it to a pdf it seems to work now …

Attachments:

  • [attachment removed: DDS.pdf]
Hi ulli,

🖼Click to load external image (Posted Image) Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please include the following in your next post:
  • ComboFix log
Below is the result.

I also got a warning from windows:

PEV.cfxxe the file c:\Dokume~1\ulrike~1\lokale~1\Temp\JETC563.tmp is demaged. Please run CHKDSK

What should I do with this message?

—————————————————-

ComboFix 10-05-12.01 - Ulrike Klöppel 12.05.2010 21:38:43.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.49.1031.18.1014.599 [GMT 1:00]
ausgeführt von:: c:\dokumente und einstellungen\Ulrike Klöppel\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.

(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.

Infizierte Kopie von c:\windows\system32\drivers\shpf.sys wurde gefunden und desinfiziert
Kopie von - Kitty had a snack :P wurde wiederhergestellt
.
((((((((((((((((((((((( Dateien erstellt von 2010-04-12 bis 2010-05-12 ))))))))))))))))))))))))))))))
.

2010-05-12 20:44 . 2010-05-12 20:44 ——– d—–w- c:\windows\LastGood
2010-05-11 07:27 . 2010-05-11 07:27 ——– d—–w- c:\programme\RegistryRestore_ERUNT
2010-05-11 02:23 . 2010-05-11 02:23 ——– d-s—w- c:\dokumente und einstellungen\NetworkService\UserData
2010-05-10 15:56 . 2010-04-29 14:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-10 15:56 . 2010-05-10 15:56 ——– d—–w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\Malwarebytes
2010-05-10 15:56 . 2010-04-29 14:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-05-10 15:56 . 2010-05-10 15:56 ——– d—–w- c:\programme\Malwarebytes' Anti-Malware
2010-05-10 14:40 . 2010-05-10 14:40 ——– d—–w- c:\programme\Trend Micro
2010-05-10 14:18 . 2010-05-10 12:25 15880 —-a-w- c:\windows\system32\lsdelete.exe
2010-05-10 12:25 . 2010-02-04 15:53 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys
2010-05-10 12:25 . 2010-05-10 12:25 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-05-10 12:22 . 2010-05-10 12:22 ——– dc-h–w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-05-10 12:22 . 2010-02-04 15:53 2954656 -c–a-w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}\Ad-AwareInstaller.exe
2010-05-10 12:21 . 2010-05-10 12:25 ——– d—–w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\Lavasoft
2010-05-10 12:21 . 2010-05-10 12:22 ——– d—–w- c:\programme\Lavasoft
2010-05-09 19:32 . 2010-05-09 19:32 ——– d—–w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\TEMP
2010-05-09 19:32 . 2010-05-09 19:34 ——– d—–w- c:\programme\SpywareBlaster
2010-04-30 23:48 . 2010-04-30 23:48 ——– d—–w- c:\programme\iPod
2010-04-30 23:48 . 2010-04-30 23:49 ——– d—–w- c:\programme\iTunes
2010-04-30 23:48 . 2010-04-30 23:49 ——– d—–w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-04-30 23:42 . 2010-04-30 23:43 ——– d—–w- c:\programme\QuickTime
2010-04-30 23:38 . 2010-04-30 23:38 ——– d—–w- c:\programme\Bonjour
2010-04-30 23:34 . 2010-04-30 23:34 73000 —-a-w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe

.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-12 20:22 . 2008-04-08 06:05 ——– d—–w- c:\programme\Mozilla Thunderbird
2010-05-11 08:15 . 2009-08-02 16:02 ——– d—–w- c:\programme\Windows Desktop Search
2010-05-10 23:09 . 2006-03-31 01:36 85594 —-a-w- c:\windows\system32\perfc007.dat
2010-05-10 23:09 . 2006-03-31 01:36 460908 —-a-w- c:\windows\system32\perfh007.dat
2010-05-07 13:10 . 2008-07-24 08:23 ——– d—–w- c:\programme\SyncBack
2010-04-30 23:48 . 2009-12-26 07:50 ——– d—–w- c:\programme\Gemeinsame Dateien\Apple
2010-04-22 18:02 . 2009-11-23 11:15 ——– d—–w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\FreePDF
2010-04-10 21:37 . 2006-03-31 11:52 ——– d—–w- c:\programme\Gemeinsame Dateien\Java
2010-04-10 21:33 . 2006-03-31 11:53 ——– d—–w- c:\programme\Java
2010-04-09 01:03 . 2010-04-09 01:03 ——– d—–w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\Langenscheidt
2010-04-09 01:02 . 2010-04-09 01:01 ——– d—–w- c:\programme\Vokabeltrainer 4-Demo
2010-04-08 20:59 . 2010-04-08 20:59 38844 —ha-w- c:\windows\system32\mlfcache.dat
2010-04-08 12:20 . 2010-04-08 12:20 91424 —-a-w- c:\windows\system32\dnssd.dll
2010-04-08 12:20 . 2010-04-08 12:20 107808 —-a-w- c:\windows\system32\dns-sd.exe
2010-04-01 12:57 . 2010-04-01 12:57 ——– d—–w- c:\programme\Gemeinsame Dateien\Skype
2010-03-14 18:19 . 2008-12-16 21:14 ——– d—–w- c:\programme\ElsterFormular
2010-03-14 18:19 . 2006-03-31 10:32 ——– d–h–w- c:\programme\InstallShield Installation Information
2010-03-09 11:09 . 2006-03-31 01:36 430080 —-a-w- c:\windows\system32\vbscript.dll
2010-03-09 03:28 . 2008-12-12 07:41 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-03-01 08:05 . 2009-03-20 22:07 124784 —-a-w- c:\windows\system32\drivers\avipbb.sys
2010-02-26 05:41 . 2006-03-31 01:36 672768 —-a-w- c:\windows\system32\wininet.dll
2010-02-26 05:41 . 2006-03-31 01:35 81920 —-a-w- c:\windows\system32\ieencode.dll
2010-02-24 13:11 . 2006-03-31 01:35 455680 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-21 10:31 . 2010-02-21 10:31 724992 —-a-w- c:\windows\iun6002.exe
2010-02-16 19:04 . 2006-03-31 01:35 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 19:04 . 2004-08-04 00:50 2027008 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-16 12:24 . 2009-03-20 22:07 60936 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2010-02-12 10:03 . 2010-03-10 20:51 293376 ——w- c:\windows\system32\browserchoice.exe
2010-02-12 04:33 . 2006-03-31 01:35 100864 —-a-w- c:\windows\system32\6to4svc.dll
.

(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SsAAD.exe"="c:\progra~1\Sony\SONICS~1\SsAAD.exe" [2006-05-08 81920]
"SpybotSD TeaTimer"="c:\programme\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Skype"="c:\programme\Skype\Phone\Skype.exe" [2010-03-09 26100520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\programme\Apoint\Apoint.exe" [2004-11-17 118784]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-17 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-17 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-17 118784]
"Mouse Suite 98 Daemon"="ICO.EXE" [2007-01-26 49152]
"EOUApp"="c:\programme\Intel\Wireless\Bin\EOUWiz.exe" [2006-02-28 569413]
"SonyPowerCfg"="c:\programme\Sony\VAIO Power Management\SPMgr.exe" [2006-01-26 212992]
"ISBMgr.exe"="c:\programme\Sony\ISB Utility\ISBMgr.exe" [2004-02-20 32768]
"zBrowser Launcher"="c:\programme\Logitech\iTouch\iTouch.exe" [2003-12-01 892928]
"Logitech Utility"="Logi_MwX.Exe" [2003-11-07 19968]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-06-20 7561216]
"IntelZeroConfig"="c:\programme\Intel\Wireless\bin\ZCfgSvc.exe" [2006-07-03 802816]
"IntelWireless"="c:\programme\Intel\Wireless\Bin\ifrmewrk.exe" [2006-07-02 700416]
"avgnt"="c:\programme\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]
"UsbBoost"="c:\programme\UsbBoost\TurboHddUsb.exe" [2009-08-11 3788800]
"FreePDF Assistant"="c:\programme\FreePDF_XP\fpassist.exe" [2009-09-05 385024]
"CanonMyPrinter"="c:\programme\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 1603152]
"SSBkgdUpdate"="c:\programme\Gemeinsame Dateien\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="c:\programme\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"WrtMon.exe"="c:\windows\system32\spool\drivers\w32x86\3\WrtMon.exe" [2006-09-20 20480]
"QuickTime Task"="c:\programme\QuickTime\QTTask.exe" [2010-03-17 421888]
"iTunesHelper"="c:\programme\iTunes\iTunesHelper.exe" [2010-04-28 142120]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\dokumente und einstellungen\All Users\Startmen\Programme\Autostart\
Acrobat Assistant.lnk - c:\programme\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-5-15 217193]
Microsoft Office.lnk - c:\programme\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2005-05-20 15:42 73728 —-a-w- c:\windows\system32\VESWinlogon.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0lsdelete

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"updateMgr"="c:\programme\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Microsoft Works Portfolio"=c:\programme\Microsoft Works\WksSb.exe /AllUsers

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programme\\Sony\\VAIO Media 5.0\\Vc.exe"=
"c:\\Programme\\FileMaker\\FileMaker Pro 8.5\\FileMaker Pro.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programme\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Programme\\Bonjour\\mDNSResponder.exe"=
"c:\\Programme\\iTunes\\iTunes.exe"=
"c:\\Programme\\Skype\\Phone\\Skype.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [10.05.2010 13:25 64288]
R0 shpf;Sony HDD Protection Filter Driver;c:\windows\system32\drivers\shpf.sys [31.03.2006 02:36 9216]
R1 FNETURPX;FNETURPX;c:\windows\system32\drivers\FNETURPX.SYS [11.08.2009 20:39 7936]
R2 AntiVirSchedulerService;Avira AntiVir Planer;c:\programme\Avira\AntiVir Desktop\sched.exe [20.03.2009 23:07 135336]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\programme\Lavasoft\Ad-Aware\AAWService.exe [04.02.2010 16:52 1285864]
R3 SPI;Sony Programmable I/O Control Device;c:\windows\system32\drivers\SonyPI.sys [31.03.2006 02:36 71961]
R3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\drivers\tap0801.sys [01.10.2006 13:37 26624]
R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [31.03.2006 02:36 226304]
S0 IFP300;iRiver Internet Audio Player IFP-300;c:\windows\system32\DRIVERS\ifp300.sys –> c:\windows\system32\DRIVERS\ifp300.sys [?]
S3 FNETTBOH;FNETTBOH;c:\windows\system32\drivers\FNETTBOH.SYS [11.08.2009 20:39 23680]
S3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\system32\drivers\SonyImgF.sys [31.03.2006 02:36 29184]
.
Inhalt des "geplante Tasks" Ordners

2010-05-10 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\programme\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 12:25]

2010-05-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programme\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
.
——- Zusätzlicher Suchlauf ——-
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = hxxp://www.club-vaio.com/de/
uInternet Settings,ProxyOverride =
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
IE: Übertragen mit Image Converter 2 Plus - c:\programme\Sony\Image Converter 2\menu.htm
Trusted Zone: microsoft.com\windowsupdate
Trusted Zone: microsoft.com\www.update
Trusted Zone: whatthetech.com\forums
FF - ProfilePath - c:\dokumente und einstellungen\Ulrike Klöppel\Anwendungsdaten\Mozilla\Firefox\Profiles\w8osac6o.default\
FF - component: c:\programme\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
FF - plugin: c:\programme\Picasa2\npPicasa2.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX Richtlinien —-
c:\programme\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\programme\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\programme\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\programme\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\programme\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\programme\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\programme\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\programme\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\programme\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\programme\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -

MSConfigStartUp-DriverCure - c:\programme\ParetoLogic\DriverCure\DriverCure.exe
MSConfigStartUp-VAIO Update 3 - c:\programme\Sony\VAIO Update 3\VAIOUpdt.exe
AddRemove-AFPL Ghostscript 8.54 - c:\programme\Ghostscript\uninstgs.exe
AddRemove-AFPL Ghostscript Fonts - c:\programme\Ghostscript\uninstgs.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-12 21:50
Windows 5.1.2600 Service Pack 3 NTFS

Scanne versteckte Prozesse…

Scanne versteckte Autostarteinträge…

Scanne versteckte Dateien…

Scan erfolgreich abgeschlossen
versteckte Dateien: 0

**************************************************************************
.
——————— Durch laufende Prozesse gestartete DLLs ———————

- - - - - - - > 'winlogon.exe'(980)
c:\windows\system32\VESWinlogon.dll
.
Zeit der Fertigstellung: 2010-05-12 21:54:57
ComboFix-quarantined-files.txt 2010-05-12 20:54

Vor Suchlauf: 9.859.026.944 Bytes frei
Nach Suchlauf: 9.926.950.912 Bytes frei

WindowsXP-KB310994-SP2-Home-BootDisk-DEU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

- - End Of File - - 710DAF4CF52C2CB2D6A59F1F2A27BDD7
ulli,

Ignore that message, but please let me know if you see it again. Please run these for me next:

🖼Click to load external image (Posted Image) Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
🖼Click to load external image (Posted Image) Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View report… at the bottom.
  • Click the Save report… button.

    [external image: Posted Image]

  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply
Please include the following in your next post:
  • MBAM log
  • Kaspersky log
  • How is your computer running?
Here is the mbam-log. As I'm leaving for a journey in an hour I can't run Kapersky now. I'll do it upon my return on Monday. Meanwhile thanks for your help! Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Datenbank Version: 4095 Windows 5.1.2600 Service Pack 3 Internet Explorer 6.0.2900.5512 13.05.2010 09:32:41 mbam-log-2010-05-13 (09-32-41).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|) Durchsuchte Objekte: 117819 Laufzeit: 59 Minute(n), 21 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 0 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: (Keine bösartigen Objekte gefunden)
Hi, I only got back to my laptop today - and upon running antivir as usual it found the following virus and put it under quarantine (see the report below). I will now run Karpersky and than come back with the report … Avira AntiVir Personal Erstellungsdatum der Reportdatei: Mittwoch, 19. Mai 2010 21:24 Es wird nach 2114057 Virenstämmen gesucht. Das Programm läuft als uneingeschränkte Vollversion. Online-Dienste stehen zur Verfügung. Lizenznehmer : Avira AntiVir Personal - FREE Antivirus Seriennummer : 0000149996-ADJIE-0000001 Plattform : Windows XP Windowsversion : (Service Pack 3) [5.1.2600] Boot Modus : Normal gebootet Benutzername : SYSTEM Computername : UK1 Versionsinformationen: BUILD.DAT : 10.0.0.567 32097 Bytes 19.04.2010 15:50:00 AVSCAN.EXE : 10.0.3.0 433832 Bytes 24.04.2010 11:11:43 AVSCAN.DLL : 10.0.3.0 56168 Bytes 24.04.2010 11:11:43 LUKE.DLL : 10.0.2.3 104296 Bytes 07.03.2010 17:32:59 LUKERES.DLL : 10.0.0.0 13672 Bytes 14.01.2010 10:59:47 VBASE000.VDF : 7.10.0.0 19875328 Bytes 06.11.2009 12:16:37 VBASE001.VDF : 7.10.1.0 1372672 Bytes 19.11.2009 12:16:37 VBASE002.VDF : 7.10.3.1 3143680 Bytes 20.01.2010 18:01:49 VBASE003.VDF : 7.10.3.75 996864 Bytes 26.01.2010 08:45:57 VBASE004.VDF : 7.10.4.203 1579008 Bytes 05.03.2010 07:22:46 VBASE005.VDF : 7.10.6.82 2494464 Bytes 15.04.2010 11:11:42 VBASE006.VDF : 7.10.6.83 2048 Bytes 15.04.2010 11:11:42 VBASE007.VDF : 7.10.6.84 2048 Bytes 15.04.2010 11:11:42 VBASE008.VDF : 7.10.6.85 2048 Bytes 15.04.2010 11:11:42 VBASE009.VDF : 7.10.6.86 2048 Bytes 15.04.2010 11:11:42 VBASE010.VDF : 7.10.6.87 2048 Bytes 15.04.2010 11:11:42 VBASE011.VDF : 7.10.6.88 2048 Bytes 15.04.2010 11:11:42 VBASE012.VDF : 7.10.6.89 2048 Bytes 15.04.2010 11:11:42 VBASE013.VDF : 7.10.6.90 2048 Bytes 15.04.2010 11:11:42 VBASE014.VDF : 7.10.6.123 126464 Bytes 19.04.2010 11:11:42 VBASE015.VDF : 7.10.6.152 123392 Bytes 21.04.2010 11:11:42 VBASE016.VDF : 7.10.6.178 122880 Bytes 22.04.2010 11:11:42 VBASE017.VDF : 7.10.6.206 120320 Bytes 26.04.2010 08:25:20 VBASE018.VDF : 7.10.6.232 99328 Bytes 28.04.2010 08:25:20 VBASE019.VDF : 7.10.7.2 155648 Bytes 30.04.2010 08:25:21 VBASE020.VDF : 7.10.7.26 119808 Bytes 04.05.2010 08:25:21 VBASE021.VDF : 7.10.7.51 118272 Bytes 06.05.2010 08:25:22 VBASE022.VDF : 7.10.7.75 404992 Bytes 10.05.2010 22:20:37 VBASE023.VDF : 7.10.7.76 2048 Bytes 10.05.2010 22:20:37 VBASE024.VDF : 7.10.7.77 2048 Bytes 10.05.2010 22:20:37 VBASE025.VDF : 7.10.7.78 2048 Bytes 10.05.2010 22:20:38 VBASE026.VDF : 7.10.7.79 2048 Bytes 10.05.2010 22:20:38 VBASE027.VDF : 7.10.7.80 2048 Bytes 10.05.2010 22:20:38 VBASE028.VDF : 7.10.7.81 2048 Bytes 10.05.2010 22:20:38 VBASE029.VDF : 7.10.7.82 2048 Bytes 10.05.2010 22:20:38 VBASE030.VDF : 7.10.7.83 2048 Bytes 10.05.2010 22:20:38 VBASE031.VDF : 7.10.7.96 120832 Bytes 12.05.2010 22:20:38 Engineversion : 8.2.1.242 AEVDF.DLL : 8.1.2.0 106868 Bytes 24.04.2010 11:11:43 AESCRIPT.DLL : [removed] 1343866 Bytes 12.05.2010 22:20:40 AESCN.DLL : [removed] 127347 Bytes 12.05.2010 22:20:39 AESBX.DLL : [removed] 254324 Bytes 24.04.2010 11:11:43 AERDL.DLL : [removed] 541043 Bytes 24.04.2010 11:11:42 AEPACK.DLL : [removed] 426358 Bytes 25.03.2010 13:05:42 AEOFFICE.DLL : 8.1.1.0 201081 Bytes 12.05.2010 22:20:39 AEHEUR.DLL : [removed] 2670967 Bytes 08.05.2010 08:25:26 AEHELP.DLL : [removed] 242039 Bytes 05.04.2010 21:51:04 AEGEN.DLL : [removed] 377203 Bytes 12.05.2010 22:20:39 AEEMU.DLL : [removed] 393588 Bytes 24.04.2010 11:11:42 AECORE.DLL : [removed] 192886 Bytes 12.05.2010 22:20:38 AEBB.DLL : 8.1.1.0 53618 Bytes 24.04.2010 11:11:42 AVWINLL.DLL : 10.0.0.0 19304 Bytes 14.01.2010 10:59:10 AVPREF.DLL : 10.0.0.0 44904 Bytes 14.01.2010 10:59:07 AVREP.DLL : 10.0.0.8 62209 Bytes 18.02.2010 15:47:40 AVREG.DLL : 10.0.3.0 53096 Bytes 24.04.2010 11:11:44 AVSCPLR.DLL : 10.0.3.0 83816 Bytes 24.04.2010 11:11:44 AVARKT.DLL : 10.0.0.14 227176 Bytes 24.04.2010 11:11:43 AVEVTLOG.DLL : 10.0.0.8 203112 Bytes 26.01.2010 08:53:25 SQLITE3.DLL : [removed] 355688 Bytes 28.01.2010 11:57:53 AVSMTP.DLL : 10.0.0.17 63848 Bytes 16.03.2010 14:38:54 NETNT.DLL : 10.0.0.0 11624 Bytes 19.02.2010 13:40:55 RCIMAGE.DLL : 10.0.0.26 2550120 Bytes 28.01.2010 12:10:08 RCTEXT.DLL : 10.0.53.0 98152 Bytes 24.04.2010 11:11:41 Konfiguration für den aktuellen Suchlauf: Job Name…………………………: Lokale Laufwerke Konfigurationsdatei……………….: C:\Programme\Avira\AntiVir Desktop\alldrives.avp Protokollierung…………………..: niedrig Primäre Aktion……………………: interaktiv Sekundäre Aktion………………….: ignorieren Durchsuche Masterbootsektoren………: ein Durchsuche Bootsektoren……………: ein Bootsektoren……………………..: C:, D:, E:, F:, Durchsuche aktive Programme………..: ein Durchsuche Registrierung…………..: ein Suche nach Rootkits……………….: aus Integritätsprüfung von Systemdateien..: aus Datei Suchmodus…………………..: Intelligente Dateiauswahl Durchsuche Archive………………..: ein Rekursionstiefe einschränken……….: 20 Archiv Smart Extensions……………: ein Makrovirenheuristik……………….: ein Dateiheuristik……………………: mittel Auszulassende Dateien……………..: G:autorun.inf, Abweichende Gefahrenkategorien……..: +JOKE,+PFS, Beginn des Suchlaufs: Mittwoch, 19. Mai 2010 21:24 Der Suchlauf über gestartete Prozesse wird begonnen: Durchsuche Prozess 'avscan.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'iPodService.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'update.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'acrotray.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'ctfmon.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'Skype.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'TeaTimer.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'SsAAD.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'iTunesHelper.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'DEVDET~1.EXE' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'WrtProc.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'WrtMon.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'OpwareSE4.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'BJMyPrt.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'Pelmiced.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'fpassist.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'TurboHddUsb.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'avgnt.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'ifrmewrk.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'ZCfgSvc.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'Logi_MwX.Exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'iTouch.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'ISBMgr.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'SPMgr.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'EOUWiz.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'ICO.EXE' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'igfxpers.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'hkcmd.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'Apntex.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'Apoint.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'wmiprvse.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'alg.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'wmiprvse.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'unsecapp.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'wmiapsrv.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'igfxsrvc.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'igfxext.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'wuauclt.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'VzFw.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'fxssvc.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'VzCdbSvc.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'VCSW.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'avshadow.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'VESMgr.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'RegSrvc.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'jqs.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'CDAC11BA.EXE' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'mDNSResponder.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'AppleMobileDeviceService.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'avguard.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'PhotoshopElementsFileAgent.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'sched.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'spoolsv.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'AAWService.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'S24EvMon.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'Explorer.EXE' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'EvtEng.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'lsass.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'services.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'winlogon.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'csrss.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'smss.exe' - '1' Modul(e) wurden durchsucht Der Suchlauf über die Masterbootsektoren wird begonnen: Masterbootsektor HD0 [INFO] Es wurde kein Virus gefunden! Masterbootsektor HD1 [INFO] Es wurde kein Virus gefunden! Der Suchlauf über die Bootsektoren wird begonnen: Bootsektor 'C:\' [INFO] Es wurde kein Virus gefunden! Bootsektor 'D:\' [INFO] Es wurde kein Virus gefunden! Bootsektor 'E:\' [INFO] Im Laufwerk 'E:\' ist kein Datenträger eingelegt! Der Suchlauf auf Verweise zu ausführbaren Dateien (Registry) wird begonnen: Die Registry wurde durchsucht ( '1795' Dateien ). Der Suchlauf über die ausgewählten Dateien wird begonnen: Beginne mit der Suche in 'C:\' C:\Qoobox\Quarantine\C\WINDOWS\system32\Drivers\shpf.sys.vir [FUND] Ist das Trojanische Pferd TR/Patched.Gen C:\System Volume Information\_restore{AEC8EE78-A184-40AD-961E-E48B00EC59FC}\RP832\A0161292.sys [FUND] Ist das Trojanische Pferd TR/Patched.Gen Beginne mit der Suche in 'D:\' Beginne mit der Suche in 'E:\' Der zu durchsuchende Pfad E:\ konnte nicht geöffnet werden! Systemfehler [21]: Das Gerät ist nicht bereit. Beginne mit der Suche in 'F:\' Der zu durchsuchende Pfad F:\ konnte nicht geöffnet werden! Systemfehler [21]: Das Gerät ist nicht bereit. Beginne mit der Desinfektion: C:\System Volume Information\_restore{AEC8EE78-A184-40AD-961E-E48B00EC59FC}\RP832\A0161292.sys [FUND] Ist das Trojanische Pferd TR/Patched.Gen [HINWEIS] Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '4ef4f829.qua' verschoben! C:\Qoobox\Quarantine\C\WINDOWS\system32\Drivers\shpf.sys.vir [FUND] Ist das Trojanische Pferd TR/Patched.Gen [HINWEIS] Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '5622d7c6.qua' verschoben! Ende des Suchlaufs: Mittwoch, 19. Mai 2010 22:47 Benötigte Zeit: 1:19:54 Stunde(n) Der Suchlauf wurde vollständig durchgeführt. 14542 Verzeichnisse wurden überprüft 417448 Dateien wurden geprüft 2 Viren bzw. unerwünschte Programme wurden gefunden 0 Dateien wurden als verdächtig eingestuft 0 Dateien wurden gelöscht 0 Viren bzw. unerwünschte Programme wurden repariert 2 Dateien wurden in die Quarantäne verschoben 0 Dateien wurden umbenannt 0 Dateien konnten nicht durchsucht werden 417446 Dateien ohne Befall 8820 Archive wurden durchsucht 0 Warnungen 2 Hinweise
Hi, The files Avira detected were from your System Restore and ComboFix's quarantine, so there is nothing concerning there. Please continue on to the Kaspersky scan.
ok, here is the result of the kaspersky-scan: ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Thursday, May 20, 2010 Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Wednesday, May 19, 2010 20:42:01 Records in database: 4138457 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ Scan statistics: Objects scanned: 107569 Threats found: 1 Infected objects found: 2 Suspicious objects found: 0 Scan duration: 03:18:43 File name / Threat / Threats count C:\Dokumente und Einstellungen\Ulrike Klöppel\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\45\352e636d-4eab7c81 Infected: Exploit.Java.Agent.f 1 C:\Dokumente und Einstellungen\Ulrike Klöppel\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\54\11c850f6-6e601624 Infected: Exploit.Java.Agent.f 1 Selected area has been scanned.
ulli,

🖼Click to load external image (Posted Image) Please download OTM
  • Save it to your desktop.
  • Please double-click OTM to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Files
    C:\Dokumente und Einstellungen\Ulrike Klöppel\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\45\352e636d-4eab7c81
    C:\Dokumente und Einstellungen\Ulrike Klöppel\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\54\11c850f6-6e601624
    
    :Commands
    [EmptyFlash]
    [EmptyTemp]
  • Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM and reboot your PC.
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Please include the following in your next post:
  • OTM log
  • How is your computer running?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI