deit
Topic Starter
Good day to everybody.
I found a thread to a similar malware problem from another user and to this forum on google.
The problem could be resolved, so I hope you can help me with it too. I have the same symptoms as radjap at http://forums.tomcoyote.org/Qwerty12_exe_t81208.html.
However I downloaded VundoFix v6.5.6, ComboFix and HijackThis v2.0.2.
These are my logs:
VundoFix:
=====
VundoFix V6.5.6
Checking Java version…
Sun Java not detected
Scan started at 06:52:39 24.07.2007
Listing files found while scanning….
C:\WINDOWS\System32\dcccf.bak1
C:\WINDOWS\System32\dcccf.ini
C:\WINDOWS\System32\fcccd.dll
Beginning removal…
Attempting to delete C:\WINDOWS\System32\dcccf.bak1
C:\WINDOWS\System32\dcccf.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\System32\dcccf.ini
C:\WINDOWS\System32\dcccf.ini Has been deleted!
Attempting to delete C:\WINDOWS\System32\fcccd.dll
C:\WINDOWS\System32\fcccd.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal…
Attempting to delete C:\WINDOWS\System32\fcccd.dll
C:\WINDOWS\System32\fcccd.dll Has been deleted!
Performing Repairs to the registry.
Done!
–
ComboFix:
=====
"deit" - 2007-07-24 7:08:53 - ComboFix 07-07-23.6 - Service Pack 1 NTFS
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\opnnnmm.dll
C:\WINDOWS\system32\opnnnmm.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\mgrs.exe
C:\WINDOWS\system32\.exe
C:\WINDOWS\system32\dhsihnxb.exe
C:\WINDOWS\system32\qcymihfu.exe
C:\WINDOWS\system32\syswin.exe
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
——-\LEGACY_DOMAINSERVICE
——-\DomainService
——-\nm
((((((((((((((((((((((((( Files Created from 2007-06-24 to 2007-07-24 )))))))))))))))))))))))))))))))
2007-07-24 07:08 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-24 06:37 d——– C:\DOKUME~1\DEIT\ANWEND~1\Prevx
2007-07-24 06:34 d——– C:\Programme\Prevx2
2007-07-24 06:34 d——– C:\DOKUME~1\ALLUSE~1\ANWEND~1\Prevx
2007-07-24 06:31 77,312 –a—— C:\WINDOWS\ua2.dll
2007-07-24 06:31 d——– C:\VundoFix Backups
2007-07-24 00:13 126,016 –a—— C:\WINDOWS\system32\tmjojxqq.dll
2007-07-24 00:04 48,824 –a—— C:\WINDOWS\system32\S32EVNT1.DLL
2007-07-24 00:04 108,728 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-07-24 00:03 d——– C:\Programme\Symantec
2007-07-24 00:03 d——– C:\DOKUME~1\ALLUSE~1\ANWEND~1\Symantec
2007-07-24 00:02 d——– C:\Programme\Gemeinsame Dateien\Symantec Shared
2007-07-24 00:01 d——– C:\Programme\Norton AntiVirus 2007
2007-07-23 23:03 76,560 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-07-23 23:02 d——– C:\DOKUME~1\DEIT\.housecall6.6
2007-07-23 22:49 d——– C:\Programme\EsetOnlineScanner
2007-07-23 05:48 d——– C:\WINDOWS\ShellNew
2007-07-23 00:05 50,688 –a—— C:\WINDOWS\system32\qwerty12.exe
2007-07-22 13:10 157,184 -ra—— C:\WINDOWS\system32\vhosts.exe
2007-07-22 12:01 dr——- C:\DOKUME~1\LOCALS~1\Favoriten
2007-07-22 12:00 d——– C:\WINDOWS\sdrive
2007-07-22 11:59 146,996 –a—— C:\nzlrs.exe
2007-07-22 09:34 d——– C:\DOKUME~1\DEIT\ANWEND~1\Teleca
2007-07-22 09:32 d——– C:\DOKUME~1\ALLUSE~1\Documents
2007-07-22 09:31 d——– C:\Programme\Gemeinsame Dateien\Teleca Shared
2007-07-22 09:31 d——– C:\DOKUME~1\ALLUSE~1\ANWEND~1\Teleca
2007-07-22 09:29 d——– C:\WINDOWS\Downloaded Installations
2007-07-22 09:29 d——– C:\Programme\InstallShield Installation Information
2007-07-22 09:28 d——– C:\Programme\QuickTime
2007-07-22 09:28 d——– C:\DOKUME~1\ALLUSE~1\ANWEND~1\Apple Computer
2007-07-22 09:06 d——– C:\DOKUME~1\DEIT\Contacts
2007-07-22 09:05 d—-c— C:\WINDOWS\system32\DRVSTORE
2007-07-22 08:57 98,816 –a—— C:\WINDOWS\system32\dmstyle.dll
2007-07-22 08:57 974,848 –a—— C:\WINDOWS\system32\dxdiag.exe
2007-07-22 08:57 83,968 –a—— C:\WINDOWS\system32\drivers\nabtsfec.sys
2007-07-22 08:57 80,896 –a—— C:\WINDOWS\system32\dpvsetup.exe
2007-07-22 08:57 8,192 –a—— C:\WINDOWS\system32\d3d8thk.dll
2007-07-22 08:57 797,184 –a—— C:\WINDOWS\system32\d3dim700.dll
2007-07-22 08:57 79,360 –a—— C:\WINDOWS\system32\dpwsockx.dll
2007-07-22 08:57 77,824 –a—— C:\WINDOWS\system32\dpmodemx.dll
2007-07-22 08:57 76,800 –a—— C:\WINDOWS\system32\dmscript.dll
2007-07-22 08:57 733,184 –a—— C:\WINDOWS\system32\qedwipes.dll
2007-07-22 08:57 723,968 –a—— C:\WINDOWS\system32\dpnet.dll
2007-07-22 08:57 7,424 –a—— C:\WINDOWS\system32\drivers\mskssrv.sys
2007-07-22 08:57 68,096 –a—— C:\WINDOWS\system32\dpnhupnp.dll
2007-07-22 08:57 64,512 –a—— C:\WINDOWS\system32\amstream.dll
2007-07-22 08:57 602,624 –a—— C:\WINDOWS\system32\dx7vb.dll
2007-07-22 08:57 58,368 –a—— C:\WINDOWS\system32\dmcompos.dll
2007-07-22 08:57 52,096 –a—— C:\WINDOWS\system32\drivers\msdv.sys
2007-07-22 08:57 5,504 –a—— C:\WINDOWS\system32\drivers\mstee.sys
2007-07-22 08:57 5,248 –a—— C:\WINDOWS\system32\drivers\mspclock.sys
2007-07-22 08:57 491,520 –a—— C:\WINDOWS\system32\dsdmoprp.dll
2007-07-22 08:57 48,512 –a—— C:\WINDOWS\system32\drivers\stream.sys
2007-07-22 08:57 470,528 –a—— C:\WINDOWS\system32\qdvd.dll
2007-07-22 08:57 47,104 –a—— C:\WINDOWS\system32\wstdecod.dll
2007-07-22 08:57 4,608 –a—— C:\WINDOWS\system32\drivers\mspqm.sys
2007-07-22 08:57 4,096 –a—— C:\WINDOWS\system32\ksuser.dll
2007-07-22 08:57 4,096 –a—— C:\WINDOWS\system32\drivers\swenum.sys
2007-07-22 08:57 381,952 –a—— C:\WINDOWS\system32\dsound.dll
2007-07-22 08:57 381,952 –a—— C:\WINDOWS\system32\dpvoice.dll
2007-07-22 08:57 354,816 –a—— C:\WINDOWS\system32\psisdecd.dll
2007-07-22 08:57 34,304 –a—— C:\WINDOWS\system32\mciqtz32.dll
2007-07-22 08:57 33,280 –a—— C:\WINDOWS\system32\dmloader.dll
2007-07-22 08:57 324,096 –a—— C:\WINDOWS\system32\mswebdvd.dll
2007-07-22 08:57 32,768 –a—— C:\WINDOWS\system32\dpnhpast.dll
2007-07-22 08:57 316,928 –a—— C:\WINDOWS\system32\qdv.dll
2007-07-22 08:57 3,072 –a—— C:\WINDOWS\system32\dpnlobby.dll
2007-07-22 08:57 3,072 –a—— C:\WINDOWS\system32\dpnaddr.dll
2007-07-22 08:57 292,864 –a—— C:\WINDOWS\system32\ddraw.dll
2007-07-22 08:57 28,160 –a—— C:\WINDOWS\system32\dplaysvr.exe
2007-07-22 08:57 27,136 –a—— C:\WINDOWS\system32\dmband.dll
2007-07-22 08:57 257,024 –a—— C:\WINDOWS\system32\qcap.dll
2007-07-22 08:57 24,064 –a—— C:\WINDOWS\system32\ddrawex.dll
2007-07-22 08:57 230,400 –a—— C:\WINDOWS\system32\dplayx.dll
2007-07-22 08:57 19,968 –a—— C:\WINDOWS\system32\dpvacm.dll
2007-07-22 08:57 186,880 –a—— C:\WINDOWS\system32\dsdmo.dll
2007-07-22 08:57 181,248 –a—— C:\WINDOWS\system32\dmime.dll
2007-07-22 08:57 18,944 –a—— C:\WINDOWS\system32\encapi.dll
2007-07-22 08:57 18,688 –a—— C:\WINDOWS\system32\drivers\wstcodec.sys
2007-07-22 08:57 18,432 –a—— C:\WINDOWS\system32\dswave.dll
2007-07-22 08:57 16,896 –a—— C:\WINDOWS\system32\msyuv.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-22 07:57:05 12,400 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-07-21 23:49:54 48,354 —-a-w C:\WINDOWS\system32\perfc007.dat
2007-07-21 23:49:54 316,924 —-a-w C:\WINDOWS\system32\perfh007.dat
2007-06-13 09:10:34 77,824 —-a-w C:\WINDOWS\system32\OnlineScannerUninstaller.exe
2007-05-16 07:18:44 95,864 —-a-w C:\WINDOWS\system32\NeroCo.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1E5FBBBE-3BF1-4909-9C2A-A9BB007BF769}]
C:\WINDOWS\System32\nnllm.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7D60E24D-47BA-41F1-BFA9-156E2F387097}]
C:\WINDOWS\System32\fcccd.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe" [2006-09-03 00:04]
"osCheck"="C:\Programme\Norton AntiVirus 2007\osCheck.exe" [2006-09-05 18:22]
"PrevxOne"="C:\Programme\Prevx2\PXConsole.exe" [2007-07-10 07:42]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [2002-08-29 03:45]
"Vhosts Protection"="C:\WINDOWS\System32\Com\vhosts.exe" []
"DAEMON Tools"="C:\Programme\DAEMON Tools\daemon.exe" [2007-04-04 00:29]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runservices]
"NiroFile Updated"=NiroFile.exe
"Auto File System Conversion Utility"=C:\WINDOWS\System32\wbem\scricon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
"Vhosts Protection"=C:\WINDOWS\System32\Com\vhosts.exe
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runservices]
"NiroFile Updated"=NiroFile.exe
"Auto File System Conversion Utility"=C:\WINDOWS\System32\wbem\scricon.exe
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"NiroFile Updated"=NiroFile.exe
"Auto File System Conversion Utility"=C:\WINDOWS\System32\wbem\scricon.exe
"Vhosts Protection"=C:\WINDOWS\System32\Com\vhosts.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"DisallowRun"=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\DisallowRun]
"Protected system files1"=avgupsvc.exe
"Protected system files2"=avgamsvr.exe
"Protected system files3"=avgcc.exe
"Protected system files4"=nod32kui.exe
"Protected system files5"=nod32krn.exe
"Protected system files6"=ccSetMgr.exe
"Protected system files7"=ccEvtMgr.exe
"Protected system files8"=DefWatch.exe
"Protected system files9"=SavRoam.exe
"Protected system files10"=Rtvscan.exe
"Protected system files11"=VPTray.exe
"Protected system files12"=ccApp.exe
"Protected system files13"=AluSchedulerSvc.exe
"Protected system files14"=nod32.exe
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"DisallowRun"=1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer\DisallowRun]
"Protected system files1"=avgupsvc.exe
"Protected system files2"=avgamsvr.exe
"Protected system files3"=avgcc.exe
"Protected system files4"=nod32kui.exe
"Protected system files5"=nod32krn.exe
"Protected system files6"=ccSetMgr.exe
"Protected system files7"=ccEvtMgr.exe
"Protected system files8"=DefWatch.exe
"Protected system files9"=SavRoam.exe
"Protected system files10"=Rtvscan.exe
"Protected system files11"=VPTray.exe
"Protected system files12"=ccApp.exe
"Protected system files13"=AluSchedulerSvc.exe
"Protected system files14"=nod32.exe
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Auto File System Conversion Utility C:\WINDOWS\System32\wbem\scricon.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"NiroFile Updated"=NiroFile.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"nwiz"=nwiz.exe /install
"QuickTime Task"="C:\Programme\QuickTime\qttask.exe" -atboottime
"NiroFile Updated"=NiroFile.exe
"smgr"=mgrs.exe
"Winamp Agent"=C:\WINDOWS\System32\winamp.exe
"icq.com"=rundll32.exe "C:\WINDOWS\System32\vcvmynos.dll",forkonce
"DXDllRegExe"=C:\WINDOWS\System32\dxdllreg.exe
"Adobe Reader Speed Launcher"="C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"Microsft Security Monitor Process"=mssmpp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices-]
"NiroFile Updated"=NiroFile.exe
"Microsft Security Monitor Process"=mssmpp.exe
R0 PrevxDriver;PREVX Kernel Mode Agent;C:\WINDOWS\System32\DRIVERS\pxfsf.sys
R1 PREVXTdi;PREVX TDI filter;C:\WINDOWS\System32\DRIVERS\pxtdi.sys
R1 PXRDDriver;PREVX Rootkitscan driver;C:\WINDOWS\System32\DRIVERS\pxrd.sys
R1 SRTSPX;SRTSPX;C:\WINDOWS\System32\Drivers\SRTSPX.SYS
R3 gameenum;Gameport-Enumerator;C:\WINDOWS\System32\DRIVERS\gameenum.sys
R3 gameport;512i digital PCI Joystick;C:\WINDOWS\System32\DRIVERS\fmjoy.sys
R3 ms_mpu401;Microsoft MPU-401 MIDI UART-Treiber;C:\WINDOWS\System32\drivers\msmpu401.sys
R3 RMSPPPOE;WAN Miniport (PPP over Ethernet Protocol);C:\WINDOWS\System32\DRIVERS\RMSPPPOE.SYS
R3 rtl8029;NT-Treiber fr Realtek RTL8029(AS)-basierter PCI-Ethernetadapter;C:\WINDOWS\System32\DRIVERS\RTL8029.SYS
R3 SRTSPL;SRTSPL;C:\WINDOWS\System32\Drivers\SRTSPL.SYS
R3 wdm_fm801;512i digital PCI Audio (WDM);C:\WINDOWS\System32\drivers\fm801.sys
S2 MSDisk;Network helper Service;"C:\WINDOWS\System32\irdvxc.exe" /service
S2 MSWindows;Network Windows Service;"C:\WINDOWS\System32\urdvxc.exe" /service
S2 pvaukrtrfa1sjk6lkoai;pvaukrtrfa1sjk6lkoai;"C:\WINDOWS\system32\svshost.exe"
S3 PREVXEmulator;PREVX Emulator driver;C:\WINDOWS\System32\DRIVERS\PxEmu.sys
S3 SRTSP;SRTSP;C:\WINDOWS\System32\Drivers\SRTSP.SYS
*Newly Created Service* - ALG
*Newly Created Service* - IPNAT
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-24 07:14:34
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden registry entries …
scanning hidden files …
**************************************************************************
Completion time: 2007-07-24 7:17:43 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-07-24 07:16
— E O F —
–
HijackThis:
=====
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 07:26:02, on 24.07.2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Programme\TuneUp Utilities 2004\WinStylerThemeSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSvcHst.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Programme\DAEMON Tools\daemon.exe
C:\Programme\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\PSIService.exe
C:\Programme\Mozilla Firefox\firefox.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Programme\Symantec\LiveUpdate\AUPDATE.EXE
C:\Programme\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Programme\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Programme\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Programme\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E5FBBBE-3BF1-4909-9C2A-A9BB007BF769} - C:\WINDOWS\System32\nnllm.dll (file missing)
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Prevx\pxbho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Windows\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7D60E24D-47BA-41F1-BFA9-156E2F387097} - C:\WINDOWS\System32\fcccd.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [ccApp] "C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Programme\Norton AntiVirus 2007\osCheck.exe"
O4 - HKLM\..\Run: [PrevxOne] "C:\Programme\Prevx2\PXConsole.exe"
O4 - HKLM\..\RunServices: [Vhosts Protection] C:\WINDOWS\System32\Com\vhosts.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Vhosts Protection] C:\WINDOWS\System32\Com\vhosts.exe
O4 - HKCU\..\RunServices: [NiroFile Updated] NiroFile.exe
O4 - HKCU\..\RunServices: [Auto File System Conversion Utility] C:\WINDOWS\System32\wbem\scricon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Vhosts Protection] C:\WINDOWS\System32\Com\vhosts.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunServices: [NiroFile Updated] NiroFile.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunServices: [NiroFile Updated] NiroFile.exe (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Windows\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Windows\Java\jre1.6.0_02\bin\ssv.dll
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/programs/OnlineScanner.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2EF9307F-5EB1-490C-8B8E-D83A4121C668}: NameServer = 217.237.150.51 217.237.148.22
O23 - Service: Automatisches LiveUpdate - Scheduler - Symantec Corporation - C:\Programme\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSvcHst.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Kennwortprüfung (ISPwdSvc) - Symantec Corporation - C:\Programme\Norton AntiVirus 2007\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Network helper Service (MSDisk) - Unknown owner - C:\WINDOWS\System32\irdvxc.exe (file missing)
O23 - Service: Network Windows Service (MSWindows) - Unknown owner - C:\WINDOWS\System32\urdvxc.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Programme\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - C:\WINDOWS\System32\nvsvc32.exe (file missing)
O23 - Service: Prevx Agent (PREVXAgent) - Prevx - C:\Programme\Prevx2\PXAgent.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\System32\PSIService.exe
O23 - Service: pvaukrtrfa1sjk6lkoai - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Windows User Mode Driver Framework (UMWdf) - Unknown owner - C:\WINDOWS\System32\wdfmgr.exe (file missing)
–
End of file - 6300 bytes
Thank you.
.:: deit ::.
I found a thread to a similar malware problem from another user and to this forum on google.
The problem could be resolved, so I hope you can help me with it too. I have the same symptoms as radjap at http://forums.tomcoyote.org/Qwerty12_exe_t81208.html.
However I downloaded VundoFix v6.5.6, ComboFix and HijackThis v2.0.2.
These are my logs:
VundoFix:
=====
VundoFix V6.5.6
Checking Java version…
Sun Java not detected
Scan started at 06:52:39 24.07.2007
Listing files found while scanning….
C:\WINDOWS\System32\dcccf.bak1
C:\WINDOWS\System32\dcccf.ini
C:\WINDOWS\System32\fcccd.dll
Beginning removal…
Attempting to delete C:\WINDOWS\System32\dcccf.bak1
C:\WINDOWS\System32\dcccf.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\System32\dcccf.ini
C:\WINDOWS\System32\dcccf.ini Has been deleted!
Attempting to delete C:\WINDOWS\System32\fcccd.dll
C:\WINDOWS\System32\fcccd.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal…
Attempting to delete C:\WINDOWS\System32\fcccd.dll
C:\WINDOWS\System32\fcccd.dll Has been deleted!
Performing Repairs to the registry.
Done!
–
ComboFix:
=====
"deit" - 2007-07-24 7:08:53 - ComboFix 07-07-23.6 - Service Pack 1 NTFS
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\opnnnmm.dll
C:\WINDOWS\system32\opnnnmm.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\mgrs.exe
C:\WINDOWS\system32\.exe
C:\WINDOWS\system32\dhsihnxb.exe
C:\WINDOWS\system32\qcymihfu.exe
C:\WINDOWS\system32\syswin.exe
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
——-\LEGACY_DOMAINSERVICE
——-\DomainService
——-\nm
((((((((((((((((((((((((( Files Created from 2007-06-24 to 2007-07-24 )))))))))))))))))))))))))))))))
2007-07-24 07:08 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-24 06:37 d——– C:\DOKUME~1\DEIT\ANWEND~1\Prevx
2007-07-24 06:34 d——– C:\Programme\Prevx2
2007-07-24 06:34 d——– C:\DOKUME~1\ALLUSE~1\ANWEND~1\Prevx
2007-07-24 06:31 77,312 –a—— C:\WINDOWS\ua2.dll
2007-07-24 06:31 d——– C:\VundoFix Backups
2007-07-24 00:13 126,016 –a—— C:\WINDOWS\system32\tmjojxqq.dll
2007-07-24 00:04 48,824 –a—— C:\WINDOWS\system32\S32EVNT1.DLL
2007-07-24 00:04 108,728 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-07-24 00:03 d——– C:\Programme\Symantec
2007-07-24 00:03 d——– C:\DOKUME~1\ALLUSE~1\ANWEND~1\Symantec
2007-07-24 00:02 d——– C:\Programme\Gemeinsame Dateien\Symantec Shared
2007-07-24 00:01 d——– C:\Programme\Norton AntiVirus 2007
2007-07-23 23:03 76,560 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-07-23 23:02 d——– C:\DOKUME~1\DEIT\.housecall6.6
2007-07-23 22:49 d——– C:\Programme\EsetOnlineScanner
2007-07-23 05:48 d——– C:\WINDOWS\ShellNew
2007-07-23 00:05 50,688 –a—— C:\WINDOWS\system32\qwerty12.exe
2007-07-22 13:10 157,184 -ra—— C:\WINDOWS\system32\vhosts.exe
2007-07-22 12:01 dr——- C:\DOKUME~1\LOCALS~1\Favoriten
2007-07-22 12:00 d——– C:\WINDOWS\sdrive
2007-07-22 11:59 146,996 –a—— C:\nzlrs.exe
2007-07-22 09:34 d——– C:\DOKUME~1\DEIT\ANWEND~1\Teleca
2007-07-22 09:32 d——– C:\DOKUME~1\ALLUSE~1\Documents
2007-07-22 09:31 d——– C:\Programme\Gemeinsame Dateien\Teleca Shared
2007-07-22 09:31 d——– C:\DOKUME~1\ALLUSE~1\ANWEND~1\Teleca
2007-07-22 09:29 d——– C:\WINDOWS\Downloaded Installations
2007-07-22 09:29 d——– C:\Programme\InstallShield Installation Information
2007-07-22 09:28 d——– C:\Programme\QuickTime
2007-07-22 09:28 d——– C:\DOKUME~1\ALLUSE~1\ANWEND~1\Apple Computer
2007-07-22 09:06 d——– C:\DOKUME~1\DEIT\Contacts
2007-07-22 09:05 d—-c— C:\WINDOWS\system32\DRVSTORE
2007-07-22 08:57 98,816 –a—— C:\WINDOWS\system32\dmstyle.dll
2007-07-22 08:57 974,848 –a—— C:\WINDOWS\system32\dxdiag.exe
2007-07-22 08:57 83,968 –a—— C:\WINDOWS\system32\drivers\nabtsfec.sys
2007-07-22 08:57 80,896 –a—— C:\WINDOWS\system32\dpvsetup.exe
2007-07-22 08:57 8,192 –a—— C:\WINDOWS\system32\d3d8thk.dll
2007-07-22 08:57 797,184 –a—— C:\WINDOWS\system32\d3dim700.dll
2007-07-22 08:57 79,360 –a—— C:\WINDOWS\system32\dpwsockx.dll
2007-07-22 08:57 77,824 –a—— C:\WINDOWS\system32\dpmodemx.dll
2007-07-22 08:57 76,800 –a—— C:\WINDOWS\system32\dmscript.dll
2007-07-22 08:57 733,184 –a—— C:\WINDOWS\system32\qedwipes.dll
2007-07-22 08:57 723,968 –a—— C:\WINDOWS\system32\dpnet.dll
2007-07-22 08:57 7,424 –a—— C:\WINDOWS\system32\drivers\mskssrv.sys
2007-07-22 08:57 68,096 –a—— C:\WINDOWS\system32\dpnhupnp.dll
2007-07-22 08:57 64,512 –a—— C:\WINDOWS\system32\amstream.dll
2007-07-22 08:57 602,624 –a—— C:\WINDOWS\system32\dx7vb.dll
2007-07-22 08:57 58,368 –a—— C:\WINDOWS\system32\dmcompos.dll
2007-07-22 08:57 52,096 –a—— C:\WINDOWS\system32\drivers\msdv.sys
2007-07-22 08:57 5,504 –a—— C:\WINDOWS\system32\drivers\mstee.sys
2007-07-22 08:57 5,248 –a—— C:\WINDOWS\system32\drivers\mspclock.sys
2007-07-22 08:57 491,520 –a—— C:\WINDOWS\system32\dsdmoprp.dll
2007-07-22 08:57 48,512 –a—— C:\WINDOWS\system32\drivers\stream.sys
2007-07-22 08:57 470,528 –a—— C:\WINDOWS\system32\qdvd.dll
2007-07-22 08:57 47,104 –a—— C:\WINDOWS\system32\wstdecod.dll
2007-07-22 08:57 4,608 –a—— C:\WINDOWS\system32\drivers\mspqm.sys
2007-07-22 08:57 4,096 –a—— C:\WINDOWS\system32\ksuser.dll
2007-07-22 08:57 4,096 –a—— C:\WINDOWS\system32\drivers\swenum.sys
2007-07-22 08:57 381,952 –a—— C:\WINDOWS\system32\dsound.dll
2007-07-22 08:57 381,952 –a—— C:\WINDOWS\system32\dpvoice.dll
2007-07-22 08:57 354,816 –a—— C:\WINDOWS\system32\psisdecd.dll
2007-07-22 08:57 34,304 –a—— C:\WINDOWS\system32\mciqtz32.dll
2007-07-22 08:57 33,280 –a—— C:\WINDOWS\system32\dmloader.dll
2007-07-22 08:57 324,096 –a—— C:\WINDOWS\system32\mswebdvd.dll
2007-07-22 08:57 32,768 –a—— C:\WINDOWS\system32\dpnhpast.dll
2007-07-22 08:57 316,928 –a—— C:\WINDOWS\system32\qdv.dll
2007-07-22 08:57 3,072 –a—— C:\WINDOWS\system32\dpnlobby.dll
2007-07-22 08:57 3,072 –a—— C:\WINDOWS\system32\dpnaddr.dll
2007-07-22 08:57 292,864 –a—— C:\WINDOWS\system32\ddraw.dll
2007-07-22 08:57 28,160 –a—— C:\WINDOWS\system32\dplaysvr.exe
2007-07-22 08:57 27,136 –a—— C:\WINDOWS\system32\dmband.dll
2007-07-22 08:57 257,024 –a—— C:\WINDOWS\system32\qcap.dll
2007-07-22 08:57 24,064 –a—— C:\WINDOWS\system32\ddrawex.dll
2007-07-22 08:57 230,400 –a—— C:\WINDOWS\system32\dplayx.dll
2007-07-22 08:57 19,968 –a—— C:\WINDOWS\system32\dpvacm.dll
2007-07-22 08:57 186,880 –a—— C:\WINDOWS\system32\dsdmo.dll
2007-07-22 08:57 181,248 –a—— C:\WINDOWS\system32\dmime.dll
2007-07-22 08:57 18,944 –a—— C:\WINDOWS\system32\encapi.dll
2007-07-22 08:57 18,688 –a—— C:\WINDOWS\system32\drivers\wstcodec.sys
2007-07-22 08:57 18,432 –a—— C:\WINDOWS\system32\dswave.dll
2007-07-22 08:57 16,896 –a—— C:\WINDOWS\system32\msyuv.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-22 07:57:05 12,400 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-07-21 23:49:54 48,354 —-a-w C:\WINDOWS\system32\perfc007.dat
2007-07-21 23:49:54 316,924 —-a-w C:\WINDOWS\system32\perfh007.dat
2007-06-13 09:10:34 77,824 —-a-w C:\WINDOWS\system32\OnlineScannerUninstaller.exe
2007-05-16 07:18:44 95,864 —-a-w C:\WINDOWS\system32\NeroCo.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1E5FBBBE-3BF1-4909-9C2A-A9BB007BF769}]
C:\WINDOWS\System32\nnllm.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7D60E24D-47BA-41F1-BFA9-156E2F387097}]
C:\WINDOWS\System32\fcccd.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe" [2006-09-03 00:04]
"osCheck"="C:\Programme\Norton AntiVirus 2007\osCheck.exe" [2006-09-05 18:22]
"PrevxOne"="C:\Programme\Prevx2\PXConsole.exe" [2007-07-10 07:42]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [2002-08-29 03:45]
"Vhosts Protection"="C:\WINDOWS\System32\Com\vhosts.exe" []
"DAEMON Tools"="C:\Programme\DAEMON Tools\daemon.exe" [2007-04-04 00:29]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runservices]
"NiroFile Updated"=NiroFile.exe
"Auto File System Conversion Utility"=C:\WINDOWS\System32\wbem\scricon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
"Vhosts Protection"=C:\WINDOWS\System32\Com\vhosts.exe
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runservices]
"NiroFile Updated"=NiroFile.exe
"Auto File System Conversion Utility"=C:\WINDOWS\System32\wbem\scricon.exe
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"NiroFile Updated"=NiroFile.exe
"Auto File System Conversion Utility"=C:\WINDOWS\System32\wbem\scricon.exe
"Vhosts Protection"=C:\WINDOWS\System32\Com\vhosts.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"DisallowRun"=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\DisallowRun]
"Protected system files1"=avgupsvc.exe
"Protected system files2"=avgamsvr.exe
"Protected system files3"=avgcc.exe
"Protected system files4"=nod32kui.exe
"Protected system files5"=nod32krn.exe
"Protected system files6"=ccSetMgr.exe
"Protected system files7"=ccEvtMgr.exe
"Protected system files8"=DefWatch.exe
"Protected system files9"=SavRoam.exe
"Protected system files10"=Rtvscan.exe
"Protected system files11"=VPTray.exe
"Protected system files12"=ccApp.exe
"Protected system files13"=AluSchedulerSvc.exe
"Protected system files14"=nod32.exe
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"DisallowRun"=1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer\DisallowRun]
"Protected system files1"=avgupsvc.exe
"Protected system files2"=avgamsvr.exe
"Protected system files3"=avgcc.exe
"Protected system files4"=nod32kui.exe
"Protected system files5"=nod32krn.exe
"Protected system files6"=ccSetMgr.exe
"Protected system files7"=ccEvtMgr.exe
"Protected system files8"=DefWatch.exe
"Protected system files9"=SavRoam.exe
"Protected system files10"=Rtvscan.exe
"Protected system files11"=VPTray.exe
"Protected system files12"=ccApp.exe
"Protected system files13"=AluSchedulerSvc.exe
"Protected system files14"=nod32.exe
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Auto File System Conversion Utility C:\WINDOWS\System32\wbem\scricon.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"NiroFile Updated"=NiroFile.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"nwiz"=nwiz.exe /install
"QuickTime Task"="C:\Programme\QuickTime\qttask.exe" -atboottime
"NiroFile Updated"=NiroFile.exe
"smgr"=mgrs.exe
"Winamp Agent"=C:\WINDOWS\System32\winamp.exe
"icq.com"=rundll32.exe "C:\WINDOWS\System32\vcvmynos.dll",forkonce
"DXDllRegExe"=C:\WINDOWS\System32\dxdllreg.exe
"Adobe Reader Speed Launcher"="C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"Microsft Security Monitor Process"=mssmpp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices-]
"NiroFile Updated"=NiroFile.exe
"Microsft Security Monitor Process"=mssmpp.exe
R0 PrevxDriver;PREVX Kernel Mode Agent;C:\WINDOWS\System32\DRIVERS\pxfsf.sys
R1 PREVXTdi;PREVX TDI filter;C:\WINDOWS\System32\DRIVERS\pxtdi.sys
R1 PXRDDriver;PREVX Rootkitscan driver;C:\WINDOWS\System32\DRIVERS\pxrd.sys
R1 SRTSPX;SRTSPX;C:\WINDOWS\System32\Drivers\SRTSPX.SYS
R3 gameenum;Gameport-Enumerator;C:\WINDOWS\System32\DRIVERS\gameenum.sys
R3 gameport;512i digital PCI Joystick;C:\WINDOWS\System32\DRIVERS\fmjoy.sys
R3 ms_mpu401;Microsoft MPU-401 MIDI UART-Treiber;C:\WINDOWS\System32\drivers\msmpu401.sys
R3 RMSPPPOE;WAN Miniport (PPP over Ethernet Protocol);C:\WINDOWS\System32\DRIVERS\RMSPPPOE.SYS
R3 rtl8029;NT-Treiber fr Realtek RTL8029(AS)-basierter PCI-Ethernetadapter;C:\WINDOWS\System32\DRIVERS\RTL8029.SYS
R3 SRTSPL;SRTSPL;C:\WINDOWS\System32\Drivers\SRTSPL.SYS
R3 wdm_fm801;512i digital PCI Audio (WDM);C:\WINDOWS\System32\drivers\fm801.sys
S2 MSDisk;Network helper Service;"C:\WINDOWS\System32\irdvxc.exe" /service
S2 MSWindows;Network Windows Service;"C:\WINDOWS\System32\urdvxc.exe" /service
S2 pvaukrtrfa1sjk6lkoai;pvaukrtrfa1sjk6lkoai;"C:\WINDOWS\system32\svshost.exe"
S3 PREVXEmulator;PREVX Emulator driver;C:\WINDOWS\System32\DRIVERS\PxEmu.sys
S3 SRTSP;SRTSP;C:\WINDOWS\System32\Drivers\SRTSP.SYS
*Newly Created Service* - ALG
*Newly Created Service* - IPNAT
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-24 07:14:34
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden registry entries …
scanning hidden files …
**************************************************************************
Completion time: 2007-07-24 7:17:43 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-07-24 07:16
— E O F —
–
HijackThis:
=====
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 07:26:02, on 24.07.2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Programme\TuneUp Utilities 2004\WinStylerThemeSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSvcHst.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Programme\DAEMON Tools\daemon.exe
C:\Programme\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\PSIService.exe
C:\Programme\Mozilla Firefox\firefox.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Programme\Symantec\LiveUpdate\AUPDATE.EXE
C:\Programme\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Programme\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Programme\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Programme\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E5FBBBE-3BF1-4909-9C2A-A9BB007BF769} - C:\WINDOWS\System32\nnllm.dll (file missing)
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Prevx\pxbho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Windows\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7D60E24D-47BA-41F1-BFA9-156E2F387097} - C:\WINDOWS\System32\fcccd.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [ccApp] "C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Programme\Norton AntiVirus 2007\osCheck.exe"
O4 - HKLM\..\Run: [PrevxOne] "C:\Programme\Prevx2\PXConsole.exe"
O4 - HKLM\..\RunServices: [Vhosts Protection] C:\WINDOWS\System32\Com\vhosts.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Vhosts Protection] C:\WINDOWS\System32\Com\vhosts.exe
O4 - HKCU\..\RunServices: [NiroFile Updated] NiroFile.exe
O4 - HKCU\..\RunServices: [Auto File System Conversion Utility] C:\WINDOWS\System32\wbem\scricon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Vhosts Protection] C:\WINDOWS\System32\Com\vhosts.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunServices: [NiroFile Updated] NiroFile.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunServices: [NiroFile Updated] NiroFile.exe (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Windows\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Windows\Java\jre1.6.0_02\bin\ssv.dll
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/programs/OnlineScanner.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2EF9307F-5EB1-490C-8B8E-D83A4121C668}: NameServer = 217.237.150.51 217.237.148.22
O23 - Service: Automatisches LiveUpdate - Scheduler - Symantec Corporation - C:\Programme\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSvcHst.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Kennwortprüfung (ISPwdSvc) - Symantec Corporation - C:\Programme\Norton AntiVirus 2007\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Network helper Service (MSDisk) - Unknown owner - C:\WINDOWS\System32\irdvxc.exe (file missing)
O23 - Service: Network Windows Service (MSWindows) - Unknown owner - C:\WINDOWS\System32\urdvxc.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Programme\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - C:\WINDOWS\System32\nvsvc32.exe (file missing)
O23 - Service: Prevx Agent (PREVXAgent) - Prevx - C:\Programme\Prevx2\PXAgent.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\System32\PSIService.exe
O23 - Service: pvaukrtrfa1sjk6lkoai - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Windows User Mode Driver Framework (UMWdf) - Unknown owner - C:\WINDOWS\System32\wdfmgr.exe (file missing)
–
End of file - 6300 bytes
Thank you.
.:: deit ::.