This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Malware (qwerty12.exe) + Logfiles

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Good day to everybody.
I found a thread to a similar malware problem from another user and to this forum on google.
The problem could be resolved, so I hope you can help me with it too. I have the same symptoms as radjap at http://forums.tomcoyote.org/Qwerty12_exe_t81208.html.

However I downloaded VundoFix v6.5.6, ComboFix and HijackThis v2.0.2.
These are my logs:




VundoFix:
=====


VundoFix V6.5.6

Checking Java version…

Sun Java not detected
Scan started at 06:52:39 24.07.2007

Listing files found while scanning….

C:\WINDOWS\System32\dcccf.bak1
C:\WINDOWS\System32\dcccf.ini
C:\WINDOWS\System32\fcccd.dll

Beginning removal…

Attempting to delete C:\WINDOWS\System32\dcccf.bak1
C:\WINDOWS\System32\dcccf.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\System32\dcccf.ini
C:\WINDOWS\System32\dcccf.ini Has been deleted!

Attempting to delete C:\WINDOWS\System32\fcccd.dll
C:\WINDOWS\System32\fcccd.dll Could not be deleted.

Performing Repairs to the registry.
Done!

Beginning removal…

Attempting to delete C:\WINDOWS\System32\fcccd.dll
C:\WINDOWS\System32\fcccd.dll Has been deleted!

Performing Repairs to the registry.
Done!




–



ComboFix:

=====


"deit" - 2007-07-24 7:08:53 - ComboFix 07-07-23.6 - Service Pack 1 NTFS


(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\opnnnmm.dll
C:\WINDOWS\system32\opnnnmm.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *



((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\mgrs.exe
C:\WINDOWS\system32\.exe
C:\WINDOWS\system32\dhsihnxb.exe
C:\WINDOWS\system32\qcymihfu.exe
C:\WINDOWS\system32\syswin.exe


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_DOMAINSERVICE
——-\DomainService
——-\nm


((((((((((((((((((((((((( Files Created from 2007-06-24 to 2007-07-24 )))))))))))))))))))))))))))))))


2007-07-24 07:08 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-24 06:37 d——– C:\DOKUME~1\DEIT\ANWEND~1\Prevx
2007-07-24 06:34 d——– C:\Programme\Prevx2
2007-07-24 06:34 d——– C:\DOKUME~1\ALLUSE~1\ANWEND~1\Prevx
2007-07-24 06:31 77,312 –a—— C:\WINDOWS\ua2.dll
2007-07-24 06:31 d——– C:\VundoFix Backups
2007-07-24 00:13 126,016 –a—— C:\WINDOWS\system32\tmjojxqq.dll
2007-07-24 00:04 48,824 –a—— C:\WINDOWS\system32\S32EVNT1.DLL
2007-07-24 00:04 108,728 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-07-24 00:03 d——– C:\Programme\Symantec
2007-07-24 00:03 d——– C:\DOKUME~1\ALLUSE~1\ANWEND~1\Symantec
2007-07-24 00:02 d——– C:\Programme\Gemeinsame Dateien\Symantec Shared
2007-07-24 00:01 d——– C:\Programme\Norton AntiVirus 2007
2007-07-23 23:03 76,560 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-07-23 23:02 d——– C:\DOKUME~1\DEIT\.housecall6.6
2007-07-23 22:49 d——– C:\Programme\EsetOnlineScanner
2007-07-23 05:48 d——– C:\WINDOWS\ShellNew
2007-07-23 00:05 50,688 –a—— C:\WINDOWS\system32\qwerty12.exe
2007-07-22 13:10 157,184 -ra—— C:\WINDOWS\system32\vhosts.exe
2007-07-22 12:01 dr——- C:\DOKUME~1\LOCALS~1\Favoriten
2007-07-22 12:00 d——– C:\WINDOWS\sdrive
2007-07-22 11:59 146,996 –a—— C:\nzlrs.exe
2007-07-22 09:34 d——– C:\DOKUME~1\DEIT\ANWEND~1\Teleca
2007-07-22 09:32 d——– C:\DOKUME~1\ALLUSE~1\Documents
2007-07-22 09:31 d——– C:\Programme\Gemeinsame Dateien\Teleca Shared
2007-07-22 09:31 d——– C:\DOKUME~1\ALLUSE~1\ANWEND~1\Teleca
2007-07-22 09:29 d——– C:\WINDOWS\Downloaded Installations
2007-07-22 09:29 d——– C:\Programme\InstallShield Installation Information
2007-07-22 09:28 d——– C:\Programme\QuickTime
2007-07-22 09:28 d——– C:\DOKUME~1\ALLUSE~1\ANWEND~1\Apple Computer
2007-07-22 09:06 d——– C:\DOKUME~1\DEIT\Contacts
2007-07-22 09:05 d—-c— C:\WINDOWS\system32\DRVSTORE
2007-07-22 08:57 98,816 –a—— C:\WINDOWS\system32\dmstyle.dll
2007-07-22 08:57 974,848 –a—— C:\WINDOWS\system32\dxdiag.exe
2007-07-22 08:57 83,968 –a—— C:\WINDOWS\system32\drivers\nabtsfec.sys
2007-07-22 08:57 80,896 –a—— C:\WINDOWS\system32\dpvsetup.exe
2007-07-22 08:57 8,192 –a—— C:\WINDOWS\system32\d3d8thk.dll
2007-07-22 08:57 797,184 –a—— C:\WINDOWS\system32\d3dim700.dll
2007-07-22 08:57 79,360 –a—— C:\WINDOWS\system32\dpwsockx.dll
2007-07-22 08:57 77,824 –a—— C:\WINDOWS\system32\dpmodemx.dll
2007-07-22 08:57 76,800 –a—— C:\WINDOWS\system32\dmscript.dll
2007-07-22 08:57 733,184 –a—— C:\WINDOWS\system32\qedwipes.dll
2007-07-22 08:57 723,968 –a—— C:\WINDOWS\system32\dpnet.dll
2007-07-22 08:57 7,424 –a—— C:\WINDOWS\system32\drivers\mskssrv.sys
2007-07-22 08:57 68,096 –a—— C:\WINDOWS\system32\dpnhupnp.dll
2007-07-22 08:57 64,512 –a—— C:\WINDOWS\system32\amstream.dll
2007-07-22 08:57 602,624 –a—— C:\WINDOWS\system32\dx7vb.dll
2007-07-22 08:57 58,368 –a—— C:\WINDOWS\system32\dmcompos.dll
2007-07-22 08:57 52,096 –a—— C:\WINDOWS\system32\drivers\msdv.sys
2007-07-22 08:57 5,504 –a—— C:\WINDOWS\system32\drivers\mstee.sys
2007-07-22 08:57 5,248 –a—— C:\WINDOWS\system32\drivers\mspclock.sys
2007-07-22 08:57 491,520 –a—— C:\WINDOWS\system32\dsdmoprp.dll
2007-07-22 08:57 48,512 –a—— C:\WINDOWS\system32\drivers\stream.sys
2007-07-22 08:57 470,528 –a—— C:\WINDOWS\system32\qdvd.dll
2007-07-22 08:57 47,104 –a—— C:\WINDOWS\system32\wstdecod.dll
2007-07-22 08:57 4,608 –a—— C:\WINDOWS\system32\drivers\mspqm.sys
2007-07-22 08:57 4,096 –a—— C:\WINDOWS\system32\ksuser.dll
2007-07-22 08:57 4,096 –a—— C:\WINDOWS\system32\drivers\swenum.sys
2007-07-22 08:57 381,952 –a—— C:\WINDOWS\system32\dsound.dll
2007-07-22 08:57 381,952 –a—— C:\WINDOWS\system32\dpvoice.dll
2007-07-22 08:57 354,816 –a—— C:\WINDOWS\system32\psisdecd.dll
2007-07-22 08:57 34,304 –a—— C:\WINDOWS\system32\mciqtz32.dll
2007-07-22 08:57 33,280 –a—— C:\WINDOWS\system32\dmloader.dll
2007-07-22 08:57 324,096 –a—— C:\WINDOWS\system32\mswebdvd.dll
2007-07-22 08:57 32,768 –a—— C:\WINDOWS\system32\dpnhpast.dll
2007-07-22 08:57 316,928 –a—— C:\WINDOWS\system32\qdv.dll
2007-07-22 08:57 3,072 –a—— C:\WINDOWS\system32\dpnlobby.dll
2007-07-22 08:57 3,072 –a—— C:\WINDOWS\system32\dpnaddr.dll
2007-07-22 08:57 292,864 –a—— C:\WINDOWS\system32\ddraw.dll
2007-07-22 08:57 28,160 –a—— C:\WINDOWS\system32\dplaysvr.exe
2007-07-22 08:57 27,136 –a—— C:\WINDOWS\system32\dmband.dll
2007-07-22 08:57 257,024 –a—— C:\WINDOWS\system32\qcap.dll
2007-07-22 08:57 24,064 –a—— C:\WINDOWS\system32\ddrawex.dll
2007-07-22 08:57 230,400 –a—— C:\WINDOWS\system32\dplayx.dll
2007-07-22 08:57 19,968 –a—— C:\WINDOWS\system32\dpvacm.dll
2007-07-22 08:57 186,880 –a—— C:\WINDOWS\system32\dsdmo.dll
2007-07-22 08:57 181,248 –a—— C:\WINDOWS\system32\dmime.dll
2007-07-22 08:57 18,944 –a—— C:\WINDOWS\system32\encapi.dll
2007-07-22 08:57 18,688 –a—— C:\WINDOWS\system32\drivers\wstcodec.sys
2007-07-22 08:57 18,432 –a—— C:\WINDOWS\system32\dswave.dll
2007-07-22 08:57 16,896 –a—— C:\WINDOWS\system32\msyuv.dll


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-22 07:57:05 12,400 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-07-21 23:49:54 48,354 —-a-w C:\WINDOWS\system32\perfc007.dat
2007-07-21 23:49:54 316,924 —-a-w C:\WINDOWS\system32\perfh007.dat
2007-06-13 09:10:34 77,824 —-a-w C:\WINDOWS\system32\OnlineScannerUninstaller.exe
2007-05-16 07:18:44 95,864 —-a-w C:\WINDOWS\system32\NeroCo.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1E5FBBBE-3BF1-4909-9C2A-A9BB007BF769}]
C:\WINDOWS\System32\nnllm.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7D60E24D-47BA-41F1-BFA9-156E2F387097}]
C:\WINDOWS\System32\fcccd.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe" [2006-09-03 00:04]
"osCheck"="C:\Programme\Norton AntiVirus 2007\osCheck.exe" [2006-09-05 18:22]
"PrevxOne"="C:\Programme\Prevx2\PXConsole.exe" [2007-07-10 07:42]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [2002-08-29 03:45]
"Vhosts Protection"="C:\WINDOWS\System32\Com\vhosts.exe" []
"DAEMON Tools"="C:\Programme\DAEMON Tools\daemon.exe" [2007-04-04 00:29]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runservices]
"NiroFile Updated"=NiroFile.exe
"Auto File System Conversion Utility"=C:\WINDOWS\System32\wbem\scricon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
"Vhosts Protection"=C:\WINDOWS\System32\Com\vhosts.exe

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runservices]
"NiroFile Updated"=NiroFile.exe
"Auto File System Conversion Utility"=C:\WINDOWS\System32\wbem\scricon.exe

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"NiroFile Updated"=NiroFile.exe
"Auto File System Conversion Utility"=C:\WINDOWS\System32\wbem\scricon.exe
"Vhosts Protection"=C:\WINDOWS\System32\Com\vhosts.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"DisallowRun"=1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\DisallowRun]
"Protected system files1"=avgupsvc.exe
"Protected system files2"=avgamsvr.exe
"Protected system files3"=avgcc.exe
"Protected system files4"=nod32kui.exe
"Protected system files5"=nod32krn.exe
"Protected system files6"=ccSetMgr.exe
"Protected system files7"=ccEvtMgr.exe
"Protected system files8"=DefWatch.exe
"Protected system files9"=SavRoam.exe
"Protected system files10"=Rtvscan.exe
"Protected system files11"=VPTray.exe
"Protected system files12"=ccApp.exe
"Protected system files13"=AluSchedulerSvc.exe
"Protected system files14"=nod32.exe

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"DisallowRun"=1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer\DisallowRun]
"Protected system files1"=avgupsvc.exe
"Protected system files2"=avgamsvr.exe
"Protected system files3"=avgcc.exe
"Protected system files4"=nod32kui.exe
"Protected system files5"=nod32krn.exe
"Protected system files6"=ccSetMgr.exe
"Protected system files7"=ccEvtMgr.exe
"Protected system files8"=DefWatch.exe
"Protected system files9"=SavRoam.exe
"Protected system files10"=Rtvscan.exe
"Protected system files11"=VPTray.exe
"Protected system files12"=ccApp.exe
"Protected system files13"=AluSchedulerSvc.exe
"Protected system files14"=nod32.exe

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Auto File System Conversion Utility C:\WINDOWS\System32\wbem\scricon.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"NiroFile Updated"=NiroFile.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"nwiz"=nwiz.exe /install
"QuickTime Task"="C:\Programme\QuickTime\qttask.exe" -atboottime
"NiroFile Updated"=NiroFile.exe
"smgr"=mgrs.exe
"Winamp Agent"=C:\WINDOWS\System32\winamp.exe
"icq.com"=rundll32.exe "C:\WINDOWS\System32\vcvmynos.dll",forkonce
"DXDllRegExe"=C:\WINDOWS\System32\dxdllreg.exe
"Adobe Reader Speed Launcher"="C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"Microsft Security Monitor Process"=mssmpp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices-]
"NiroFile Updated"=NiroFile.exe
"Microsft Security Monitor Process"=mssmpp.exe

R0 PrevxDriver;PREVX Kernel Mode Agent;C:\WINDOWS\System32\DRIVERS\pxfsf.sys
R1 PREVXTdi;PREVX TDI filter;C:\WINDOWS\System32\DRIVERS\pxtdi.sys
R1 PXRDDriver;PREVX Rootkitscan driver;C:\WINDOWS\System32\DRIVERS\pxrd.sys
R1 SRTSPX;SRTSPX;C:\WINDOWS\System32\Drivers\SRTSPX.SYS
R3 gameenum;Gameport-Enumerator;C:\WINDOWS\System32\DRIVERS\gameenum.sys
R3 gameport;512i digital PCI Joystick;C:\WINDOWS\System32\DRIVERS\fmjoy.sys
R3 ms_mpu401;Microsoft MPU-401 MIDI UART-Treiber;C:\WINDOWS\System32\drivers\msmpu401.sys
R3 RMSPPPOE;WAN Miniport (PPP over Ethernet Protocol);C:\WINDOWS\System32\DRIVERS\RMSPPPOE.SYS
R3 rtl8029;NT-Treiber fr Realtek RTL8029(AS)-basierter PCI-Ethernetadapter;C:\WINDOWS\System32\DRIVERS\RTL8029.SYS
R3 SRTSPL;SRTSPL;C:\WINDOWS\System32\Drivers\SRTSPL.SYS
R3 wdm_fm801;512i digital PCI Audio (WDM);C:\WINDOWS\System32\drivers\fm801.sys
S2 MSDisk;Network helper Service;"C:\WINDOWS\System32\irdvxc.exe" /service
S2 MSWindows;Network Windows Service;"C:\WINDOWS\System32\urdvxc.exe" /service
S2 pvaukrtrfa1sjk6lkoai;pvaukrtrfa1sjk6lkoai;"C:\WINDOWS\system32\svshost.exe"
S3 PREVXEmulator;PREVX Emulator driver;C:\WINDOWS\System32\DRIVERS\PxEmu.sys
S3 SRTSP;SRTSP;C:\WINDOWS\System32\Drivers\SRTSP.SYS

*Newly Created Service* - ALG
*Newly Created Service* - IPNAT

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-24 07:14:34
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden registry entries …

scanning hidden files …

**************************************************************************

Completion time: 2007-07-24 7:17:43 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-07-24 07:16

— E O F —




–


HijackThis:

=====


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 07:26:02, on 24.07.2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Programme\TuneUp Utilities 2004\WinStylerThemeSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSvcHst.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Programme\DAEMON Tools\daemon.exe
C:\Programme\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\PSIService.exe
C:\Programme\Mozilla Firefox\firefox.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Programme\Symantec\LiveUpdate\AUPDATE.EXE
C:\Programme\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Programme\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Programme\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Programme\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E5FBBBE-3BF1-4909-9C2A-A9BB007BF769} - C:\WINDOWS\System32\nnllm.dll (file missing)
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Prevx\pxbho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Windows\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7D60E24D-47BA-41F1-BFA9-156E2F387097} - C:\WINDOWS\System32\fcccd.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [ccApp] "C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Programme\Norton AntiVirus 2007\osCheck.exe"
O4 - HKLM\..\Run: [PrevxOne] "C:\Programme\Prevx2\PXConsole.exe"
O4 - HKLM\..\RunServices: [Vhosts Protection] C:\WINDOWS\System32\Com\vhosts.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Vhosts Protection] C:\WINDOWS\System32\Com\vhosts.exe
O4 - HKCU\..\RunServices: [NiroFile Updated] NiroFile.exe
O4 - HKCU\..\RunServices: [Auto File System Conversion Utility] C:\WINDOWS\System32\wbem\scricon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Vhosts Protection] C:\WINDOWS\System32\Com\vhosts.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunServices: [NiroFile Updated] NiroFile.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunServices: [NiroFile Updated] NiroFile.exe (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Windows\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Windows\Java\jre1.6.0_02\bin\ssv.dll
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/programs/OnlineScanner.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2EF9307F-5EB1-490C-8B8E-D83A4121C668}: NameServer = 217.237.150.51 217.237.148.22
O23 - Service: Automatisches LiveUpdate - Scheduler - Symantec Corporation - C:\Programme\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSvcHst.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Kennwortprüfung (ISPwdSvc) - Symantec Corporation - C:\Programme\Norton AntiVirus 2007\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Network helper Service (MSDisk) - Unknown owner - C:\WINDOWS\System32\irdvxc.exe (file missing)
O23 - Service: Network Windows Service (MSWindows) - Unknown owner - C:\WINDOWS\System32\urdvxc.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Programme\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - C:\WINDOWS\System32\nvsvc32.exe (file missing)
O23 - Service: Prevx Agent (PREVXAgent) - Prevx - C:\Programme\Prevx2\PXAgent.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\System32\PSIService.exe
O23 - Service: pvaukrtrfa1sjk6lkoai - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Windows User Mode Driver Framework (UMWdf) - Unknown owner - C:\WINDOWS\System32\wdfmgr.exe (file missing)

–
End of file - 6300 bytes



Thank you.
.:: deit ::.
That's a rather nastily infested PC you have there

One or more of the identified infections is a backdoor trojan.

This allows hackers to remotely control your computer, steal critical system information and Download and Execute files

I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the Trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

When Should I Format, How Should I Reinstall

However, if you do not have the resources to reinstall your computer and would like me to attempt to clean it, I will be happy to do so.

Should you have any questions, please feel free to ask.

Please let us know what you have decided to do in your next post.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI