FilmFreak85
Topic Starter
Hey!
I read a thread about a problem that sounded very similar to mine and I tried the suggestions mentioned there (Sorry for my bad English, I'm from Germany and sometimes I can't find the words I need). Here's the link to this thread:
http://forums.whatthetech.com/wowfx_dll_errors_t87427.html
First of all I ran ATF Cleaner as described, then I ran ComboFix. Before that I had this awful program Antivirus XP 2008 and couldn't remove it, and suddenly my antivirus program detected "wowfx.dll". Everytime I deleted it, it came back. hunreds of times. I couldn't do anything on my PC. And now there's nothing. No virus alert, and it seems that Antivirus XP 2008 has disappeared. But I'm not sure. Here is the log file from ComboFix:
ComboFix 08-09-05.02 - chris 2008-09-07 0:32:49.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.0.1252.1.1031.18.666 [GMT 2:00]
ausgeführt von:: C:\Dokumente und Einstellungen\chris\Desktop\ComboFix.exe
* Neuer Wiederherstellungspunkt wurde erstellt
Achtung - Auf diesem PC ist keine Wiederherstellungskonsole installiert !!
.
(((((((((((((((((((((((((((((((((((( Weitere L”schungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Dokumente und Einstellungen\All Users\Desktop\Antivirus XP 2008.lnk
C:\Dokumente und Einstellungen\All Users\Startmenü\Online Security Guide.url
C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Antivirus XP 2008
C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Antivirus XP 2008.lnk
C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Antivirus XP 2008\Antivirus XP 2008.lnk
C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Antivirus XP 2008\How to Register Antivirus XP 2008.lnk
C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Antivirus XP 2008\License Agreement.lnk
C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Antivirus XP 2008\Register Antivirus XP 2008.lnk
C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Antivirus XP 2008\Uninstall.lnk
C:\Dokumente und Einstellungen\All Users\Startmenü\Security Troubleshooting.url
C:\Dokumente und Einstellungen\chris\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\Antivirus XP 2008.lnk
C:\Dokumente und Einstellungen\chris\Anwendungsdaten\rhccn2j0eed5
C:\Dokumente und Einstellungen\chris\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Dokumente und Einstellungen\Gast\Anwendungsdaten\wsnpoem
C:\Dokumente und Einstellungen\Gast\Anwendungsdaten\wsnpoem\audio.dll
C:\Programme\altcmd
C:\Programme\altcmd\almd32.dll
C:\Programme\altcmd\altcmd.inf
C:\Programme\altcmd\altcmd32.dll
C:\Programme\altcmd\uninstall.bat
C:\WINDOWS\crock+mock.config
C:\WINDOWS\svw.exe
C:\WINDOWS\svx.exe
C:\WINDOWS\system32\actskn43.ocx
C:\WINDOWS\system32\blphc9n2j0eed5.scr
C:\WINDOWS\system32\cache329
C:\WINDOWS\system32\dllh8jkd1q8.exe
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\lphc9n2j0eed5.exe
C:\WINDOWS\system32\Packet.dll
C:\WINDOWS\system32\pfxzmtsmtspm.dll
C:\WINDOWS\system32\pthreadVC.dll
C:\WINDOWS\system32\sfxzmtwbmail.dll
C:\WINDOWS\system32\svcp.csv
C:\WINDOWS\system32\WanPacket.dll
C:\WINDOWS\system32\winsub.xml
C:\WINDOWS\system32\wowfx.dll
C:\WINDOWS\system32\wpcap.dll
C:\WINDOWS\vlc.exe
C:\WINDOWS\wdmon.exe
.
((((((((((((((((((((((((((((((((((((((( Treiber/Dienste )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_MICROSOFT_INT_SERVICE
——-\Legacy_MSDIRECT
——-\Legacy_NPF
——-\Service_Microsoft Int Service
——-\Service_msdirect
——-\Service_NPF
((((((((((((((((((((((( Dateien erstellt von 2008-08-06 bis 2008-09-06 ))))))))))))))))))))))))))))))
.
2008-09-06 14:30 . 2008-09-06 22:41 951 –a—— C:\WINDOWS\win.tmp
2008-09-06 14:30 . 2008-09-06 22:41 227 –a—— C:\WINDOWS\system.tmp
2008-09-06 14:03 . 2008-09-06 14:27 d——– C:\Programme\Spyware Doctor
2008-09-06 14:03 . 2008-09-06 14:03 d——– C:\Dokumente und Einstellungen\chris\Anwendungsdaten\PC Tools
2008-09-05 21:37 . 2008-09-05 21:37 d——– C:\Dokumente und Einstellungen\Pascal\Anwendungsdaten\Publish Providers
2008-09-05 21:37 . 2008-09-05 21:37 d——– C:\Dokumente und Einstellungen\Pascal\Anwendungsdaten\NetMedia Providers
2008-09-05 21:36 . 2008-09-05 21:36 d——– C:\Dokumente und Einstellungen\Pascal\Anwendungsdaten\Sonic Foundry
2008-09-05 18:46 . 2008-09-06 14:01 d-a—— C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP
2008-09-02 23:20 . 2008-09-02 23:20 d——– C:\Dokumente und Einstellungen\Pascal\Anwendungsdaten\EverAd
2008-09-01 02:55 . 2005-12-31 06:45 57,856 –a—— C:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\nvsvc1024.dll
2008-08-31 19:57 . 2008-08-31 19:57 d——– C:\Programme\Enigma Software Group
2008-08-31 14:48 . 2008-08-31 19:50 d——– C:\google.com
2008-08-31 14:34 . 2008-08-31 14:47 d——– C:\AntivirAsistant
2008-08-31 14:32 . 2008-08-31 14:32 d——– C:\WINDOWS\system32\xlib254.dll
2008-08-31 14:32 . 2008-08-31 14:32 d——– C:\WINDOWS\system32\append.dll
2008-08-31 13:55 . 2008-09-03 23:17 d——– C:\Programme\rhccn2j0eed5
2008-08-31 11:35 . 2008-08-31 11:35 144 –ahs—- C:\WINDOWS\system32\2295825253.dat
2008-08-27 18:33 . 2008-08-27 18:33 d——– C:\Programme\No23 Recorder
2008-08-20 14:47 . 2008-08-20 14:47 d——– C:\Dokumente und Einstellungen\chris\Anwendungsdaten\EverAd
2008-08-11 09:40 . 2008-08-11 09:40 d——– C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Apple
2008-08-07 21:44 . 2008-08-07 21:44 24,576 –a—— C:\WINDOWS\system32\prefscpl.cpl
2008-08-07 21:44 . 2008-08-07 21:44 8,552 –a—— C:\WINDOWS\system32\drivers\asctrm.sys
2008-08-07 21:24 . 2008-08-07 21:24 d——– C:\Dokumente und Einstellungen\Pascal\Anwendungsdaten\Roxio
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-06 20:38 ——— d—–w C:\Programme\eMule
2008-09-06 17:55 ——— d—–w C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\AntiVir PersonalEdition Classic
2008-09-05 16:34 ——— d—–w C:\Programme\Napster
2008-08-29 13:00 ——— d—–w C:\Programme\Norton Security Scan
2008-08-27 16:41 ——— d—–w C:\Dokumente und Einstellungen\chris\Anwendungsdaten\BitTorrent
2008-08-15 13:03 ——— d—–w C:\Programme\Gemeinsame Dateien\Symantec Shared
2008-08-11 07:40 ——— d—–w C:\Programme\Apple Software Update
2008-08-07 19:44 ——— d—–w C:\Programme\Gemeinsame Dateien\Real
2008-08-06 15:56 ——— d—–w C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\DVD Shrink
2008-08-04 13:48 ——— d—–w C:\Programme\SpyHunter
2008-08-02 02:33 ——— d—–w C:\Dokumente und Einstellungen\chris\Anwendungsdaten\DNA
2008-07-29 14:54 ——— d—–w C:\Dokumente und Einstellungen\chris\Anwendungsdaten\Roxio
2008-07-29 13:07 ——— d—–w C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Napster
2008-07-29 12:43 ——— d—–w C:\Programme\Gemeinsame Dateien\Napster Shared
2008-07-29 12:42 ——— d–h–w C:\Programme\InstallShield Installation Information
2008-07-29 12:42 ——— d—–w C:\Programme\Gemeinsame Dateien\InstallShield
2008-07-23 23:03 ——— d—–w C:\Programme\Opera
2008-07-16 19:39 ——— d—–w C:\Programme\Xvid
2008-07-16 19:39 ——— d—–w C:\Programme\aTube Catcher 1.0
2008-07-09 17:23 ——— d—–w C:\Programme\Lexmark X1100 Series
.
——- Sigcheck ——-
2004-08-04 09:58 14336 65a819b121eb6fdab4400ea42bdffe64 C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\svchost.exe
2001-08-18 12:00 12800 adbb33d5893bcf08e75ea54bb5669205 C:\WINDOWS\system32\svchost.exe
2001-08-18 12:00 12800 adbb33d5893bcf08e75ea54bb5669205 C:\WINDOWS\system32\dllcache\svchost.exe
2004-08-04 09:57 578560 56785fd5236d7b22cf471a6da9db46d8 C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\user32.dll
2001-08-18 12:00 562688 6873d38e021eac4e0b508d1822157c1d C:\WINDOWS\system32\user32.dll
2001-08-18 12:00 562688 6873d38e021eac4e0b508d1822157c1d C:\WINDOWS\system32\dllcache\user32.dll
2004-08-04 09:57 82944 d569240a22421d5f670bb6fb6dd522b5 C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\ws2_32.dll
2001-08-18 12:00 75264 ae894c124feb008ad1876ef655967685 C:\WINDOWS\system32\ws2_32.dll
2001-08-18 12:00 75264 ae894c124feb008ad1876ef655967685 C:\WINDOWS\system32\dllcache\ws2_32.dll
2001-08-18 12:00 599552 b3b023b390f7ab35900d87ae4474a045 C:\WINDOWS\$NtUninstallKB834707-IE6-20040929.115007$\wininet.dll
2004-08-23 19:15 590336 4893f7e1495c3265fd2d8f764de1c10a C:\WINDOWS\f57cf602052e37abb1453dcbc909\wininet.dll
2004-08-04 09:57 662016 b1a1da99c4a6ebfd59f86a453bf02f39 C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\wininet.dll
2004-08-23 19:15 590336 4893f7e1495c3265fd2d8f764de1c10a C:\WINDOWS\system32\WININET.DLL
2004-08-23 19:15 590336 4893f7e1495c3265fd2d8f764de1c10a C:\WINDOWS\system32\dllcache\WININET.DLL
2004-08-04 08:14 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\tcpip.sys
2001-08-18 12:00 327168 e7774698bb0d14b0710a9a31e209f9b6 C:\WINDOWS\system32\dllcache\tcpip.sys
2001-08-18 12:00 327168 e7774698bb0d14b0710a9a31e209f9b6 C:\WINDOWS\system32\drivers\tcpip.sys
2004-08-04 09:58 507392 2b6a0baf33a9918f09442d873848ff72 C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\winlogon.exe
2001-08-18 12:00 435200 5dac883c68d261d406489f3f990d8ddf C:\WINDOWS\system32\winlogon.exe
2001-08-18 12:00 435200 5dac883c68d261d406489f3f990d8ddf C:\WINDOWS\system32\dllcache\winlogon.exe
2004-08-04 08:14 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\ndis.sys
2001-08-18 12:00 161536 3efd4f59ba0a340de0a3ab984001dbf7 C:\WINDOWS\system32\dllcache\ndis.sys
2001-08-18 12:00 161536 3efd4f59ba0a340de0a3ab984001dbf7 C:\WINDOWS\system32\drivers\ndis.sys
2004-08-04 09:50 2059136 ce41fc4c06499a389d39b301879535fb C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\ntkrnlpa.exe
2001-08-18 12:00 1899008 09bfaa5d4d15b4d307d91cfd198fabc1 C:\WINDOWS\system32\ntkrnlpa.exe
2004-08-04 09:50 2183296 dc888c9c4ca0eea7a3cb7e6b610f75c7 C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\ntoskrnl.exe
2001-08-18 12:00 1984512 3ba950b403060180606235bbb955a315 C:\WINDOWS\system32\ntoskrnl.exe
2001-08-18 12:00 1004032 d1a32c0c43f7cb53050042fd631020d9 C:\WINDOWS\explorer.exe
2004-08-04 09:57 1035264 22fe1be02eadde1632e478e4125639e0 C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\explorer.exe
2001-08-18 12:00 1004032 d1a32c0c43f7cb53050042fd631020d9 C:\WINDOWS\system32\dllcache\explorer.exe
2004-08-04 09:58 108544 edb6b81761bd60f32f740bbc40afb676 C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\services.exe
2001-08-18 12:00 101888 a87c3a6b407fb3b22c566315607ce229 C:\WINDOWS\system32\services.exe
2001-08-18 12:00 101888 a87c3a6b407fb3b22c566315607ce229 C:\WINDOWS\system32\dllcache\services.exe
2004-08-04 09:57 13312 183805eb05bca5a1e4aaaed4d2be3690 C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\lsass.exe
2001-08-18 12:00 11776 06df1b4d51bea83cf16fd45ab8c8cce8 C:\WINDOWS\system32\lsass.exe
2001-08-18 12:00 11776 06df1b4d51bea83cf16fd45ab8c8cce8 C:\WINDOWS\system32\dllcache\lsass.exe
2004-08-04 09:57 15360 7ce20569925df6789c31799f0c538f29 C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\ctfmon.exe
2001-08-18 12:00 13312 d7ce89274b884b6b59764d96b49003df C:\WINDOWS\system32\ctfmon.exe
2001-08-18 12:00 13312 d7ce89274b884b6b59764d96b49003df C:\WINDOWS\system32\dllcache\ctfmon.exe
2004-08-04 09:58 57856 54e7113a4bd696e430919bcaf5c65e06 C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\spoolsv.exe
2001-08-18 12:00 51200 9b627e6da0ea47a3a664f69d954831d7 C:\WINDOWS\system32\spoolsv.exe
2001-08-18 12:00 51200 9b627e6da0ea47a3a664f69d954831d7 C:\WINDOWS\system32\dllcache\spoolsv.exe
2004-08-04 09:58 25088 d1e53dc57143f2584b1dd53b036c0633 C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\userinit.exe
2001-08-18 12:00 22016 292f283d9e2d49a91df039c1076acd18 C:\WINDOWS\system32\userinit.exe
2001-08-18 12:00 22016 292f283d9e2d49a91df039c1076acd18 C:\WINDOWS\system32\dllcache\userinit.exe
.
(((((((((((((((((((((((((((( Autostart Punkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Eintrage & legitime Standardeintrage werden nicht angezeigt.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Spyware Doctor"="C:\Programme\Spyware Doctor\swdoctor.exe" [2005-10-12 1695504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-18 266497]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2006-10-22 7700480]
"NvMediaCenter"="NvMCTray.dll" [2006-10-22 C:\WINDOWS\system32\nvmctray.dll]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2001-08-18 13312]
"Spyware Doctor"="C:\Programme\Spyware Doctor\swdoctor.exe" [2005-10-12 1695504]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.PIM1"= PCLEPIM1.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
UpdateWin REG_SZ C:\WINDOWS\System32\adsldpcn.exe
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Adobe Acrobat - Schnellstart.lnk]
path=C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Adobe Acrobat - Schnellstart.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat - Schnellstart.lnkCommon Startup
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Google Updater.lnk]
path=C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Google Updater.lnk
backup=C:\WINDOWS\pss\Google Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^MightyFAX Controller.lnk]
path=C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\MightyFAX Controller.lnk
backup=C:\WINDOWS\pss\MightyFAX Controller.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
–a—— 2006-01-12 21:52 483328 C:\Programme\Adobe\Adobe Acrobat 7.0\Distillr\acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2007-05-11 03:06 40048 C:\Programme\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Version Cue CS2]
–a—— 2005-04-06 17:53 856064 C:\Programme\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
–a—— 2008-03-25 01:25 587568 C:\Programme\BitTorrent\bittorrent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
–a—— 2008-05-08 17:00 289088 C:\Programme\DNA\btdna.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eMuleAutoStart]
–a—— 2007-05-13 16:57 5308416 C:\Programme\eMule\emule.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ Lite]
–a—— 2006-07-11 12:15 3144800 C:\Programme\ICQLite\ICQLite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2007-06-01 16:51 257088 C:\Programme\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X1100 Series]
–a—— 2003-08-19 16:51 57344 C:\Programme\Lexmark X1100 Series\lxbkbmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mp4 Player]
–a—— 2007-03-14 11:36 598528 C:\Programme\Mp4 Player\Mp4Player.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2001-08-02 08:14 1077277 C:\Programme\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NapsterShell]
–a—— 2007-01-12 19:36 323216 C:\Programme\Napster\napster.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2007-04-27 09:41 282624 C:\Programme\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
–a—— 2008-08-07 21:44 26112 C:\Programme\Real\RealPlayer\realplay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMrhccn2j0eed5]
–a—— 2008-08-31 08:26 831488 C:\Programme\rhccn2j0eed5\rhccn2j0eed5.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
–a—— 2005-05-31 02:04 1415824 C:\Programme\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpyHunter Security Suite]
–a—— 2008-06-19 16:48 851968 C:\Programme\Enigma Software Group\SpyHunter\SpyHunter3.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
–a—— 2007-07-20 18:54 68856 C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
–a—— 2006-03-30 17:45 313472 C:\Programme\Adobe\Adobe Acrobat 7.0\Acrobat\AdobeUpdateManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirtualCloneDrive]
–a—— 2005-04-12 17:27 45056 C:\Programme\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"TUWinStylerThemeSvc"=3 (0x3)
"LexBceS"=2 (0x2)
"iPod Service"=3 (0x3)
"gusvc"=2 (0x2)
"Adobe Version Cue CS2"=3 (0x3)
"Adobe LM Service"=3 (0x3)
"accsvc"=2 (0x2)
"sdCoreService"=3 (0x3)
"sdAuxService"=3 (0x3)
"AdminSVCff"=2 (0x2)
"aawservice"=2 (0x2)
"Microsoft Int Service"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="C:\Programme\QuickTime\qttask.exe" -atboottime
"SunJavaUpdateSched"="C:\Programme\Java\jre1.6.0_03\bin\jusched.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Programme\\BitTorrent\\bittorrent.exe"=
R0 avgntmgr;avgntmgr;C:\WINDOWS\System32\drivers\avgntmgr.sys [2008-05-16 22336]
R1 avgntdd;avgntdd;C:\WINDOWS\System32\DRIVERS\avgntdd.sys [2008-07-18 45376]
R2 ALIEHCD;ALi PCI to USB Enhanced Host Controller;C:\WINDOWS\System32\Drivers\ALIEHCI.sys [2003-12-18 112835]
R3 aliroothub;USB 2.0 Root Hub;C:\WINDOWS\System32\DRIVERS\AliRtHub.sys [2003-12-18 5325]
R3 ULI5261XP;ULi M526X Ethernet NT Driver;C:\WINDOWS\System32\DRIVERS\ULILAN51.SYS [2005-03-22 28672]
S2 dnlsvc;MS Software Shadow Download Provider;C:\DOKUME~1\chris\LOKALE~1\Temp\bloadd.exe [ ]
S3 aligp;USB Composite Device;C:\WINDOWS\System32\DRIVERS\AliGP.sys [2003-12-18 8656]
S4 accsvc;AccSys WiFi Component;C:\Programme\Gemeinsame Dateien\AccSys\accsvc.exe [2006-01-11 147456]
S4 AdminSVCff;WEB.DE Firefox Update;C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Web.de Firefox\adminsvcff.exe [2006-10-25 180224]
*Newly Created Service* - ALG
*Newly Created Service* - IPNAT
*Newly Created Service* - SHAREDACCESS
.
Inhalt des "geplante Tasks" Ordners
.
- - - - Entfernte verwaiste Registrierungseintr„ge - - - -
HKCU-Run-CDriver - c:\google.com\svchost.exe
HKCU-Run-DDriver - c:\google.com\svchost.exe
HKCU-Run-alpha - c:\google.com\svchost.exe
HKCU-Run-beta - c:\google.com\svchost.exe
HKCU-Run-gamma - c:\google.com\svchost.exe
HKCU-Run-DriverLoad - (no file)
HKCU-Run-DriverCheck - (no file)
HKCU-Run-SystemDriverLoad - (no file)
HKCU-Run-SystemDriver - (no file)
HKCU-Run-FDriver - (no file)
HKCU-Run-ADriver - (no file)
HKU-Default-Run-CDriver - c:\google.com\svchost.exe
HKU-Default-Run-DDriver - c:\google.com\svchost.exe
HKU-Default-Run-alpha - c:\google.com\svchost.exe
HKU-Default-Run-beta - c:\google.com\svchost.exe
HKU-Default-Run-gamma - c:\google.com\svchost.exe
HKU-Default-Run-neos - C:\WINDOWS\neos.exe
HKU-Default-Run-DriverLoad - (no file)
HKU-Default-Run-DriverCheck - (no file)
HKU-Default-Run-SystemDriverLoad - (no file)
HKU-Default-Run-SystemDriver - (no file)
HKU-Default-Run-FDriver - (no file)
HKU-Default-Run-ADriver - (no file)
MSConfigStartUp-alpha - c:\google.com\svchost.exe
MSConfigStartUp-beta - c:\google.com\svchost.exe
MSConfigStartUp-CDriver - c:\google.com\svchost.exe
MSConfigStartUp-DDriver - c:\google.com\svchost.exe
MSConfigStartUp-gamma - c:\google.com\svchost.exe
MSConfigStartUp-lphc9n2j0eed5 - C:\WINDOWS\System32\lphc9n2j0eed5.exe
MSConfigStartUp-neos - C:\WINDOWS\neos.exe
MSConfigStartUp-net64 - C:\WINDOWS\svhoster.exe
MSConfigStartUp-netc - C:\WINDOWS\svc.exe
MSConfigStartUp-netw - C:\WINDOWS\svw.exe
MSConfigStartUp-netx - C:\WINDOWS\svx.exe
MSConfigStartUp-PromoReg - C:\WINDOWS\System32\alt.exe.exe
MSConfigStartUp-TkBellExe - C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe
MSConfigStartUp-UpdateWin - C:\WINDOWS\System32\adsldpcn.exe
MSConfigStartUp-vlc - C:\WINDOWS\vlc.exe
MSConfigStartUp-wdmon - C:\WINDOWS\wdmon.exe
.
——- Zus„tzlicher Scan ——-
.
FireFox -: Profile - C:\Dokumente und Einstellungen\chris\Anwendungsdaten\Mozilla\Firefox\Profiles\xbmldgxg.default\
FF -: plugin - C:\Programme\DNA\plugins\npbtdna.dll
FF -: plugin - C:\Programme\Google\Google Updater\2.1.919.23132\npCIDetect11.dll
FF -: plugin - C:\Programme\Mozilla Firefox\plugins\npbittorrent.dll
FF -: plugin - C:\Programme\Mozilla Firefox\plugins\npstrlnk.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-07 01:08:13
Windows 5.1.2600 NTFS
Scanne versteckte Prozesse…
Scanne versteckte Autostart Eintr„ge…
Scanne versteckte Dateien…
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\C:\WINDOWS\TEMP\mc22.tmp"
.
———————— Weitere, laufende Prozesse ————————
.
C:\Programme\AntiVir PersonalEdition Classic\sched.exe
C:\Programme\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Programme\PurgeIE\PurgeIE_Service.exe
C:\Programme\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\wdfmgr.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2008-09-07 1:13:44 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2008-09-06 23:13:37
Pre-Run: 4,823,519,232 Bytes frei
Post-Run: 4,983,873,536 Bytes frei
330
And here is the log file from HijackThis (I made it after ComboFix):
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 01:19:10, on 07.09.2008
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\AntiVir PersonalEdition Classic\sched.exe
C:\Programme\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Programme\PurgeIE\PurgeIE_Service.exe
C:\Programme\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\explorer.exe
C:\Programme\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.arcor.de
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programme\google\googletoolbar3.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programme\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: GVDownloader - {ae4df123-9140-4f93-9b32-ff0186389cc3} - mscoree.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programme\google\googletoolbar3.dll
O4 - HKLM\..\Run: [avgnt] "C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Programme\Spyware Doctor\swdoctor.exe" /Q
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Ausgewählte Verknüpfungen in Adobe PDF konvertieren - res://C:\Programme\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Ausgewählte Verknüpfungen in vorhandene PDF-Datei konvertieren - res://C:\Programme\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Auswahl in Adobe PDF konvertieren - res://C:\Programme\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Auswahl in vorhandene PDF-Datei konvertieren - res://C:\Programme\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Download Video - http://www.viloader.net/addon.htm
O8 - Extra context menu item: In Adobe PDF konvertieren - res://C:\Programme\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: In vorhandene PDF-Datei konvertieren - res://C:\Programme\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Verknüpfungsziel in Adobe PDF konvertieren - res://C:\Programme\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Verknüpfungsziel in vorhandene PDF-Datei konvertieren - res://C:\Programme\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O12 - Plugin for .spop: C:\Programme\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {59136DB4-6CA3-4B40-8F2F-BBF84B6F1E91} (Attachment Upload Control) - https://stream.web.de/mail/activex/mail_upload_11213.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1190410336546
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://static.pe.studivz.net/photouploader…ache=1203179236
O16 - DPF: {96512D57-F751-4088-A689-5778FCC77F7A} (Photo Uploader Control) - http://www.studivz.net/lib/photouploader/PhotoUploader.cab
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - http://www.moviegroup.tv/activex/DownloadMgr.cab
O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} (Image Uploader Control) - http://static.pe.studivz.net/photouploader…ache=1216374845
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.com/Register/Br…018/flashax.cab
O23 - Service: AntiVir PersonalEdition Classic Planer (AntiVirScheduler) - Avira GmbH - C:\Programme\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Programme\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: MS Software Shadow Download Provider (dnlsvc) - Unknown owner - C:\DOKUME~1\chris\LOKALE~1\Temp\bloadd.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PurgeIE XP Service (PurgeIEservice) - Assistance & Resources for Computing, Inc. - C:\Programme\PurgeIE\PurgeIE_Service.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools - C:\Programme\Spyware Doctor\sdhelp.exe
–
End of file - 7790 bytes
Can you help me?
Thanks a lot!!!
I read a thread about a problem that sounded very similar to mine and I tried the suggestions mentioned there (Sorry for my bad English, I'm from Germany and sometimes I can't find the words I need). Here's the link to this thread:
http://forums.whatthetech.com/wowfx_dll_errors_t87427.html
First of all I ran ATF Cleaner as described, then I ran ComboFix. Before that I had this awful program Antivirus XP 2008 and couldn't remove it, and suddenly my antivirus program detected "wowfx.dll". Everytime I deleted it, it came back. hunreds of times. I couldn't do anything on my PC. And now there's nothing. No virus alert, and it seems that Antivirus XP 2008 has disappeared. But I'm not sure. Here is the log file from ComboFix:
ComboFix 08-09-05.02 - chris 2008-09-07 0:32:49.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.0.1252.1.1031.18.666 [GMT 2:00]
ausgeführt von:: C:\Dokumente und Einstellungen\chris\Desktop\ComboFix.exe
* Neuer Wiederherstellungspunkt wurde erstellt
Achtung - Auf diesem PC ist keine Wiederherstellungskonsole installiert !!
.
(((((((((((((((((((((((((((((((((((( Weitere L”schungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Dokumente und Einstellungen\All Users\Desktop\Antivirus XP 2008.lnk
C:\Dokumente und Einstellungen\All Users\Startmenü\Online Security Guide.url
C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Antivirus XP 2008
C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Antivirus XP 2008.lnk
C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Antivirus XP 2008\Antivirus XP 2008.lnk
C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Antivirus XP 2008\How to Register Antivirus XP 2008.lnk
C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Antivirus XP 2008\License Agreement.lnk
C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Antivirus XP 2008\Register Antivirus XP 2008.lnk
C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Antivirus XP 2008\Uninstall.lnk
C:\Dokumente und Einstellungen\All Users\Startmenü\Security Troubleshooting.url
C:\Dokumente und Einstellungen\chris\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\Antivirus XP 2008.lnk
C:\Dokumente und Einstellungen\chris\Anwendungsdaten\rhccn2j0eed5
C:\Dokumente und Einstellungen\chris\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Dokumente und Einstellungen\Gast\Anwendungsdaten\wsnpoem
C:\Dokumente und Einstellungen\Gast\Anwendungsdaten\wsnpoem\audio.dll
C:\Programme\altcmd
C:\Programme\altcmd\almd32.dll
C:\Programme\altcmd\altcmd.inf
C:\Programme\altcmd\altcmd32.dll
C:\Programme\altcmd\uninstall.bat
C:\WINDOWS\crock+mock.config
C:\WINDOWS\svw.exe
C:\WINDOWS\svx.exe
C:\WINDOWS\system32\actskn43.ocx
C:\WINDOWS\system32\blphc9n2j0eed5.scr
C:\WINDOWS\system32\cache329
C:\WINDOWS\system32\dllh8jkd1q8.exe
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\lphc9n2j0eed5.exe
C:\WINDOWS\system32\Packet.dll
C:\WINDOWS\system32\pfxzmtsmtspm.dll
C:\WINDOWS\system32\pthreadVC.dll
C:\WINDOWS\system32\sfxzmtwbmail.dll
C:\WINDOWS\system32\svcp.csv
C:\WINDOWS\system32\WanPacket.dll
C:\WINDOWS\system32\winsub.xml
C:\WINDOWS\system32\wowfx.dll
C:\WINDOWS\system32\wpcap.dll
C:\WINDOWS\vlc.exe
C:\WINDOWS\wdmon.exe
.
((((((((((((((((((((((((((((((((((((((( Treiber/Dienste )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_MICROSOFT_INT_SERVICE
——-\Legacy_MSDIRECT
——-\Legacy_NPF
——-\Service_Microsoft Int Service
——-\Service_msdirect
——-\Service_NPF
((((((((((((((((((((((( Dateien erstellt von 2008-08-06 bis 2008-09-06 ))))))))))))))))))))))))))))))
.
2008-09-06 14:30 . 2008-09-06 22:41 951 –a—— C:\WINDOWS\win.tmp
2008-09-06 14:30 . 2008-09-06 22:41 227 –a—— C:\WINDOWS\system.tmp
2008-09-06 14:03 . 2008-09-06 14:27 d——– C:\Programme\Spyware Doctor
2008-09-06 14:03 . 2008-09-06 14:03 d——– C:\Dokumente und Einstellungen\chris\Anwendungsdaten\PC Tools
2008-09-05 21:37 . 2008-09-05 21:37 d——– C:\Dokumente und Einstellungen\Pascal\Anwendungsdaten\Publish Providers
2008-09-05 21:37 . 2008-09-05 21:37 d——– C:\Dokumente und Einstellungen\Pascal\Anwendungsdaten\NetMedia Providers
2008-09-05 21:36 . 2008-09-05 21:36 d——– C:\Dokumente und Einstellungen\Pascal\Anwendungsdaten\Sonic Foundry
2008-09-05 18:46 . 2008-09-06 14:01 d-a—— C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP
2008-09-02 23:20 . 2008-09-02 23:20 d——– C:\Dokumente und Einstellungen\Pascal\Anwendungsdaten\EverAd
2008-09-01 02:55 . 2005-12-31 06:45 57,856 –a—— C:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\nvsvc1024.dll
2008-08-31 19:57 . 2008-08-31 19:57 d——– C:\Programme\Enigma Software Group
2008-08-31 14:48 . 2008-08-31 19:50 d——– C:\google.com
2008-08-31 14:34 . 2008-08-31 14:47 d——– C:\AntivirAsistant
2008-08-31 14:32 . 2008-08-31 14:32 d——– C:\WINDOWS\system32\xlib254.dll
2008-08-31 14:32 . 2008-08-31 14:32 d——– C:\WINDOWS\system32\append.dll
2008-08-31 13:55 . 2008-09-03 23:17 d——– C:\Programme\rhccn2j0eed5
2008-08-31 11:35 . 2008-08-31 11:35 144 –ahs—- C:\WINDOWS\system32\2295825253.dat
2008-08-27 18:33 . 2008-08-27 18:33 d——– C:\Programme\No23 Recorder
2008-08-20 14:47 . 2008-08-20 14:47 d——– C:\Dokumente und Einstellungen\chris\Anwendungsdaten\EverAd
2008-08-11 09:40 . 2008-08-11 09:40 d——– C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Apple
2008-08-07 21:44 . 2008-08-07 21:44 24,576 –a—— C:\WINDOWS\system32\prefscpl.cpl
2008-08-07 21:44 . 2008-08-07 21:44 8,552 –a—— C:\WINDOWS\system32\drivers\asctrm.sys
2008-08-07 21:24 . 2008-08-07 21:24 d——– C:\Dokumente und Einstellungen\Pascal\Anwendungsdaten\Roxio
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-06 20:38 ——— d—–w C:\Programme\eMule
2008-09-06 17:55 ——— d—–w C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\AntiVir PersonalEdition Classic
2008-09-05 16:34 ——— d—–w C:\Programme\Napster
2008-08-29 13:00 ——— d—–w C:\Programme\Norton Security Scan
2008-08-27 16:41 ——— d—–w C:\Dokumente und Einstellungen\chris\Anwendungsdaten\BitTorrent
2008-08-15 13:03 ——— d—–w C:\Programme\Gemeinsame Dateien\Symantec Shared
2008-08-11 07:40 ——— d—–w C:\Programme\Apple Software Update
2008-08-07 19:44 ——— d—–w C:\Programme\Gemeinsame Dateien\Real
2008-08-06 15:56 ——— d—–w C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\DVD Shrink
2008-08-04 13:48 ——— d—–w C:\Programme\SpyHunter
2008-08-02 02:33 ——— d—–w C:\Dokumente und Einstellungen\chris\Anwendungsdaten\DNA
2008-07-29 14:54 ——— d—–w C:\Dokumente und Einstellungen\chris\Anwendungsdaten\Roxio
2008-07-29 13:07 ——— d—–w C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Napster
2008-07-29 12:43 ——— d—–w C:\Programme\Gemeinsame Dateien\Napster Shared
2008-07-29 12:42 ——— d–h–w C:\Programme\InstallShield Installation Information
2008-07-29 12:42 ——— d—–w C:\Programme\Gemeinsame Dateien\InstallShield
2008-07-23 23:03 ——— d—–w C:\Programme\Opera
2008-07-16 19:39 ——— d—–w C:\Programme\Xvid
2008-07-16 19:39 ——— d—–w C:\Programme\aTube Catcher 1.0
2008-07-09 17:23 ——— d—–w C:\Programme\Lexmark X1100 Series
.
——- Sigcheck ——-
2004-08-04 09:58 14336 65a819b121eb6fdab4400ea42bdffe64 C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\svchost.exe
2001-08-18 12:00 12800 adbb33d5893bcf08e75ea54bb5669205 C:\WINDOWS\system32\svchost.exe
2001-08-18 12:00 12800 adbb33d5893bcf08e75ea54bb5669205 C:\WINDOWS\system32\dllcache\svchost.exe
2004-08-04 09:57 578560 56785fd5236d7b22cf471a6da9db46d8 C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\user32.dll
2001-08-18 12:00 562688 6873d38e021eac4e0b508d1822157c1d C:\WINDOWS\system32\user32.dll
2001-08-18 12:00 562688 6873d38e021eac4e0b508d1822157c1d C:\WINDOWS\system32\dllcache\user32.dll
2004-08-04 09:57 82944 d569240a22421d5f670bb6fb6dd522b5 C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\ws2_32.dll
2001-08-18 12:00 75264 ae894c124feb008ad1876ef655967685 C:\WINDOWS\system32\ws2_32.dll
2001-08-18 12:00 75264 ae894c124feb008ad1876ef655967685 C:\WINDOWS\system32\dllcache\ws2_32.dll
2001-08-18 12:00 599552 b3b023b390f7ab35900d87ae4474a045 C:\WINDOWS\$NtUninstallKB834707-IE6-20040929.115007$\wininet.dll
2004-08-23 19:15 590336 4893f7e1495c3265fd2d8f764de1c10a C:\WINDOWS\f57cf602052e37abb1453dcbc909\wininet.dll
2004-08-04 09:57 662016 b1a1da99c4a6ebfd59f86a453bf02f39 C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\wininet.dll
2004-08-23 19:15 590336 4893f7e1495c3265fd2d8f764de1c10a C:\WINDOWS\system32\WININET.DLL
2004-08-23 19:15 590336 4893f7e1495c3265fd2d8f764de1c10a C:\WINDOWS\system32\dllcache\WININET.DLL
2004-08-04 08:14 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\tcpip.sys
2001-08-18 12:00 327168 e7774698bb0d14b0710a9a31e209f9b6 C:\WINDOWS\system32\dllcache\tcpip.sys
2001-08-18 12:00 327168 e7774698bb0d14b0710a9a31e209f9b6 C:\WINDOWS\system32\drivers\tcpip.sys
2004-08-04 09:58 507392 2b6a0baf33a9918f09442d873848ff72 C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\winlogon.exe
2001-08-18 12:00 435200 5dac883c68d261d406489f3f990d8ddf C:\WINDOWS\system32\winlogon.exe
2001-08-18 12:00 435200 5dac883c68d261d406489f3f990d8ddf C:\WINDOWS\system32\dllcache\winlogon.exe
2004-08-04 08:14 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\ndis.sys
2001-08-18 12:00 161536 3efd4f59ba0a340de0a3ab984001dbf7 C:\WINDOWS\system32\dllcache\ndis.sys
2001-08-18 12:00 161536 3efd4f59ba0a340de0a3ab984001dbf7 C:\WINDOWS\system32\drivers\ndis.sys
2004-08-04 09:50 2059136 ce41fc4c06499a389d39b301879535fb C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\ntkrnlpa.exe
2001-08-18 12:00 1899008 09bfaa5d4d15b4d307d91cfd198fabc1 C:\WINDOWS\system32\ntkrnlpa.exe
2004-08-04 09:50 2183296 dc888c9c4ca0eea7a3cb7e6b610f75c7 C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\ntoskrnl.exe
2001-08-18 12:00 1984512 3ba950b403060180606235bbb955a315 C:\WINDOWS\system32\ntoskrnl.exe
2001-08-18 12:00 1004032 d1a32c0c43f7cb53050042fd631020d9 C:\WINDOWS\explorer.exe
2004-08-04 09:57 1035264 22fe1be02eadde1632e478e4125639e0 C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\explorer.exe
2001-08-18 12:00 1004032 d1a32c0c43f7cb53050042fd631020d9 C:\WINDOWS\system32\dllcache\explorer.exe
2004-08-04 09:58 108544 edb6b81761bd60f32f740bbc40afb676 C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\services.exe
2001-08-18 12:00 101888 a87c3a6b407fb3b22c566315607ce229 C:\WINDOWS\system32\services.exe
2001-08-18 12:00 101888 a87c3a6b407fb3b22c566315607ce229 C:\WINDOWS\system32\dllcache\services.exe
2004-08-04 09:57 13312 183805eb05bca5a1e4aaaed4d2be3690 C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\lsass.exe
2001-08-18 12:00 11776 06df1b4d51bea83cf16fd45ab8c8cce8 C:\WINDOWS\system32\lsass.exe
2001-08-18 12:00 11776 06df1b4d51bea83cf16fd45ab8c8cce8 C:\WINDOWS\system32\dllcache\lsass.exe
2004-08-04 09:57 15360 7ce20569925df6789c31799f0c538f29 C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\ctfmon.exe
2001-08-18 12:00 13312 d7ce89274b884b6b59764d96b49003df C:\WINDOWS\system32\ctfmon.exe
2001-08-18 12:00 13312 d7ce89274b884b6b59764d96b49003df C:\WINDOWS\system32\dllcache\ctfmon.exe
2004-08-04 09:58 57856 54e7113a4bd696e430919bcaf5c65e06 C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\spoolsv.exe
2001-08-18 12:00 51200 9b627e6da0ea47a3a664f69d954831d7 C:\WINDOWS\system32\spoolsv.exe
2001-08-18 12:00 51200 9b627e6da0ea47a3a664f69d954831d7 C:\WINDOWS\system32\dllcache\spoolsv.exe
2004-08-04 09:58 25088 d1e53dc57143f2584b1dd53b036c0633 C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\userinit.exe
2001-08-18 12:00 22016 292f283d9e2d49a91df039c1076acd18 C:\WINDOWS\system32\userinit.exe
2001-08-18 12:00 22016 292f283d9e2d49a91df039c1076acd18 C:\WINDOWS\system32\dllcache\userinit.exe
.
(((((((((((((((((((((((((((( Autostart Punkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Eintrage & legitime Standardeintrage werden nicht angezeigt.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Spyware Doctor"="C:\Programme\Spyware Doctor\swdoctor.exe" [2005-10-12 1695504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-18 266497]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2006-10-22 7700480]
"NvMediaCenter"="NvMCTray.dll" [2006-10-22 C:\WINDOWS\system32\nvmctray.dll]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2001-08-18 13312]
"Spyware Doctor"="C:\Programme\Spyware Doctor\swdoctor.exe" [2005-10-12 1695504]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.PIM1"= PCLEPIM1.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
UpdateWin REG_SZ C:\WINDOWS\System32\adsldpcn.exe
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Adobe Acrobat - Schnellstart.lnk]
path=C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Adobe Acrobat - Schnellstart.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat - Schnellstart.lnkCommon Startup
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Google Updater.lnk]
path=C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Google Updater.lnk
backup=C:\WINDOWS\pss\Google Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^MightyFAX Controller.lnk]
path=C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\MightyFAX Controller.lnk
backup=C:\WINDOWS\pss\MightyFAX Controller.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
–a—— 2006-01-12 21:52 483328 C:\Programme\Adobe\Adobe Acrobat 7.0\Distillr\acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2007-05-11 03:06 40048 C:\Programme\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Version Cue CS2]
–a—— 2005-04-06 17:53 856064 C:\Programme\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
–a—— 2008-03-25 01:25 587568 C:\Programme\BitTorrent\bittorrent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
–a—— 2008-05-08 17:00 289088 C:\Programme\DNA\btdna.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eMuleAutoStart]
–a—— 2007-05-13 16:57 5308416 C:\Programme\eMule\emule.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ Lite]
–a—— 2006-07-11 12:15 3144800 C:\Programme\ICQLite\ICQLite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2007-06-01 16:51 257088 C:\Programme\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X1100 Series]
–a—— 2003-08-19 16:51 57344 C:\Programme\Lexmark X1100 Series\lxbkbmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mp4 Player]
–a—— 2007-03-14 11:36 598528 C:\Programme\Mp4 Player\Mp4Player.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2001-08-02 08:14 1077277 C:\Programme\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NapsterShell]
–a—— 2007-01-12 19:36 323216 C:\Programme\Napster\napster.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2007-04-27 09:41 282624 C:\Programme\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
–a—— 2008-08-07 21:44 26112 C:\Programme\Real\RealPlayer\realplay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMrhccn2j0eed5]
–a—— 2008-08-31 08:26 831488 C:\Programme\rhccn2j0eed5\rhccn2j0eed5.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
–a—— 2005-05-31 02:04 1415824 C:\Programme\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpyHunter Security Suite]
–a—— 2008-06-19 16:48 851968 C:\Programme\Enigma Software Group\SpyHunter\SpyHunter3.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
–a—— 2007-07-20 18:54 68856 C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
–a—— 2006-03-30 17:45 313472 C:\Programme\Adobe\Adobe Acrobat 7.0\Acrobat\AdobeUpdateManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirtualCloneDrive]
–a—— 2005-04-12 17:27 45056 C:\Programme\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"TUWinStylerThemeSvc"=3 (0x3)
"LexBceS"=2 (0x2)
"iPod Service"=3 (0x3)
"gusvc"=2 (0x2)
"Adobe Version Cue CS2"=3 (0x3)
"Adobe LM Service"=3 (0x3)
"accsvc"=2 (0x2)
"sdCoreService"=3 (0x3)
"sdAuxService"=3 (0x3)
"AdminSVCff"=2 (0x2)
"aawservice"=2 (0x2)
"Microsoft Int Service"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="C:\Programme\QuickTime\qttask.exe" -atboottime
"SunJavaUpdateSched"="C:\Programme\Java\jre1.6.0_03\bin\jusched.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Programme\\BitTorrent\\bittorrent.exe"=
R0 avgntmgr;avgntmgr;C:\WINDOWS\System32\drivers\avgntmgr.sys [2008-05-16 22336]
R1 avgntdd;avgntdd;C:\WINDOWS\System32\DRIVERS\avgntdd.sys [2008-07-18 45376]
R2 ALIEHCD;ALi PCI to USB Enhanced Host Controller;C:\WINDOWS\System32\Drivers\ALIEHCI.sys [2003-12-18 112835]
R3 aliroothub;USB 2.0 Root Hub;C:\WINDOWS\System32\DRIVERS\AliRtHub.sys [2003-12-18 5325]
R3 ULI5261XP;ULi M526X Ethernet NT Driver;C:\WINDOWS\System32\DRIVERS\ULILAN51.SYS [2005-03-22 28672]
S2 dnlsvc;MS Software Shadow Download Provider;C:\DOKUME~1\chris\LOKALE~1\Temp\bloadd.exe [ ]
S3 aligp;USB Composite Device;C:\WINDOWS\System32\DRIVERS\AliGP.sys [2003-12-18 8656]
S4 accsvc;AccSys WiFi Component;C:\Programme\Gemeinsame Dateien\AccSys\accsvc.exe [2006-01-11 147456]
S4 AdminSVCff;WEB.DE Firefox Update;C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Web.de Firefox\adminsvcff.exe [2006-10-25 180224]
*Newly Created Service* - ALG
*Newly Created Service* - IPNAT
*Newly Created Service* - SHAREDACCESS
.
Inhalt des "geplante Tasks" Ordners
.
- - - - Entfernte verwaiste Registrierungseintr„ge - - - -
HKCU-Run-CDriver - c:\google.com\svchost.exe
HKCU-Run-DDriver - c:\google.com\svchost.exe
HKCU-Run-alpha - c:\google.com\svchost.exe
HKCU-Run-beta - c:\google.com\svchost.exe
HKCU-Run-gamma - c:\google.com\svchost.exe
HKCU-Run-DriverLoad - (no file)
HKCU-Run-DriverCheck - (no file)
HKCU-Run-SystemDriverLoad - (no file)
HKCU-Run-SystemDriver - (no file)
HKCU-Run-FDriver - (no file)
HKCU-Run-ADriver - (no file)
HKU-Default-Run-CDriver - c:\google.com\svchost.exe
HKU-Default-Run-DDriver - c:\google.com\svchost.exe
HKU-Default-Run-alpha - c:\google.com\svchost.exe
HKU-Default-Run-beta - c:\google.com\svchost.exe
HKU-Default-Run-gamma - c:\google.com\svchost.exe
HKU-Default-Run-neos - C:\WINDOWS\neos.exe
HKU-Default-Run-DriverLoad - (no file)
HKU-Default-Run-DriverCheck - (no file)
HKU-Default-Run-SystemDriverLoad - (no file)
HKU-Default-Run-SystemDriver - (no file)
HKU-Default-Run-FDriver - (no file)
HKU-Default-Run-ADriver - (no file)
MSConfigStartUp-alpha - c:\google.com\svchost.exe
MSConfigStartUp-beta - c:\google.com\svchost.exe
MSConfigStartUp-CDriver - c:\google.com\svchost.exe
MSConfigStartUp-DDriver - c:\google.com\svchost.exe
MSConfigStartUp-gamma - c:\google.com\svchost.exe
MSConfigStartUp-lphc9n2j0eed5 - C:\WINDOWS\System32\lphc9n2j0eed5.exe
MSConfigStartUp-neos - C:\WINDOWS\neos.exe
MSConfigStartUp-net64 - C:\WINDOWS\svhoster.exe
MSConfigStartUp-netc - C:\WINDOWS\svc.exe
MSConfigStartUp-netw - C:\WINDOWS\svw.exe
MSConfigStartUp-netx - C:\WINDOWS\svx.exe
MSConfigStartUp-PromoReg - C:\WINDOWS\System32\alt.exe.exe
MSConfigStartUp-TkBellExe - C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe
MSConfigStartUp-UpdateWin - C:\WINDOWS\System32\adsldpcn.exe
MSConfigStartUp-vlc - C:\WINDOWS\vlc.exe
MSConfigStartUp-wdmon - C:\WINDOWS\wdmon.exe
.
——- Zus„tzlicher Scan ——-
.
FireFox -: Profile - C:\Dokumente und Einstellungen\chris\Anwendungsdaten\Mozilla\Firefox\Profiles\xbmldgxg.default\
FF -: plugin - C:\Programme\DNA\plugins\npbtdna.dll
FF -: plugin - C:\Programme\Google\Google Updater\2.1.919.23132\npCIDetect11.dll
FF -: plugin - C:\Programme\Mozilla Firefox\plugins\npbittorrent.dll
FF -: plugin - C:\Programme\Mozilla Firefox\plugins\npstrlnk.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-07 01:08:13
Windows 5.1.2600 NTFS
Scanne versteckte Prozesse…
Scanne versteckte Autostart Eintr„ge…
Scanne versteckte Dateien…
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\C:\WINDOWS\TEMP\mc22.tmp"
.
———————— Weitere, laufende Prozesse ————————
.
C:\Programme\AntiVir PersonalEdition Classic\sched.exe
C:\Programme\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Programme\PurgeIE\PurgeIE_Service.exe
C:\Programme\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\wdfmgr.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2008-09-07 1:13:44 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2008-09-06 23:13:37
Pre-Run: 4,823,519,232 Bytes frei
Post-Run: 4,983,873,536 Bytes frei
330
And here is the log file from HijackThis (I made it after ComboFix):
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 01:19:10, on 07.09.2008
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\AntiVir PersonalEdition Classic\sched.exe
C:\Programme\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Programme\PurgeIE\PurgeIE_Service.exe
C:\Programme\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\explorer.exe
C:\Programme\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.arcor.de
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programme\google\googletoolbar3.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programme\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: GVDownloader - {ae4df123-9140-4f93-9b32-ff0186389cc3} - mscoree.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programme\google\googletoolbar3.dll
O4 - HKLM\..\Run: [avgnt] "C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Programme\Spyware Doctor\swdoctor.exe" /Q
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Ausgewählte Verknüpfungen in Adobe PDF konvertieren - res://C:\Programme\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Ausgewählte Verknüpfungen in vorhandene PDF-Datei konvertieren - res://C:\Programme\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Auswahl in Adobe PDF konvertieren - res://C:\Programme\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Auswahl in vorhandene PDF-Datei konvertieren - res://C:\Programme\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Download Video - http://www.viloader.net/addon.htm
O8 - Extra context menu item: In Adobe PDF konvertieren - res://C:\Programme\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: In vorhandene PDF-Datei konvertieren - res://C:\Programme\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Verknüpfungsziel in Adobe PDF konvertieren - res://C:\Programme\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Verknüpfungsziel in vorhandene PDF-Datei konvertieren - res://C:\Programme\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O12 - Plugin for .spop: C:\Programme\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {59136DB4-6CA3-4B40-8F2F-BBF84B6F1E91} (Attachment Upload Control) - https://stream.web.de/mail/activex/mail_upload_11213.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1190410336546
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://static.pe.studivz.net/photouploader…ache=1203179236
O16 - DPF: {96512D57-F751-4088-A689-5778FCC77F7A} (Photo Uploader Control) - http://www.studivz.net/lib/photouploader/PhotoUploader.cab
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - http://www.moviegroup.tv/activex/DownloadMgr.cab
O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} (Image Uploader Control) - http://static.pe.studivz.net/photouploader…ache=1216374845
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.com/Register/Br…018/flashax.cab
O23 - Service: AntiVir PersonalEdition Classic Planer (AntiVirScheduler) - Avira GmbH - C:\Programme\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Programme\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: MS Software Shadow Download Provider (dnlsvc) - Unknown owner - C:\DOKUME~1\chris\LOKALE~1\Temp\bloadd.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PurgeIE XP Service (PurgeIEservice) - Assistance & Resources for Computing, Inc. - C:\Programme\PurgeIE\PurgeIE_Service.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools - C:\Programme\Spyware Doctor\sdhelp.exe
–
End of file - 7790 bytes
Can you help me?
Thanks a lot!!!