This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] malware popups in IE under Vista

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi guys, I am currently having trouble with several popups of the Internetexplorer. Adware and even kaspersky couldn't solve the problem. It found a few malware freescan[2].htm files in my temporary internetfiles, several cookies and stuff but it seems that everything gets restored after I use the IE once. So the main problem couldn't be detected by any anti-virus software I tried.
(Sorry for my bad english by the way.. I am german :smack: )

Here is the hijackthis log file right after I restarted my PC . Opera and kaspersky were running. I hope this isn't a problem. If it is, please tell me! :blush:
If you want me to do some special things (except of posting funny pics of me :yeah:) , please tell me.
Thank you so much for even reading this! :notworthy:


Logfile of HijackThis v1.99.1
Scan saved at 21:43:07, on 16.10.2008
Platform: Unknown Windows (WinNT 6.00.1905 SP1)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {47AA614C-73EF-4A3F-95C3-9722EEEEFC59} - (no file)
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: (no name) - {622A9D44-CB10-4619-B081-B6EF08000D74} - (no file)
O2 - BHO: (no name) - {7523E09B-A424-4D43-9D65-E930D06855BF} - (no file)
O2 - BHO: (no name) - {7604A914-4D06-43C9-B167-26921EBD0C41} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {794DAF00-83AA-4AE5-9E20-D39EFA1588ED} - (no file)
O2 - BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {90D93A9E-25B2-4F84-8333-FCD2F11F6A19} - (no file)
O2 - BHO: (no name) - {938F9DCE-F7E6-4345-BD77-3395674751EE} - (no file)
O2 - BHO: (no name) - {972EFC7D-6CFF-4D23-81CE-8C003B8B870D} - C:\Windows\system32\wVPFyXNg.dll
O2 - BHO: (no name) - {AF2A34BC-8EC9-426A-BE33-3D50A1939B34} - (no file)
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: (no name) - {D26DD9BA-554A-4620-B37F-D5C0CA9C6803} - (no file)
O2 - BHO: (no name) - {D6A5C38C-A954-4207-9FED-184BCB29C8FE} - C:\Windows\system32\tuvSjHXO.dll
O2 - BHO: {9ddc288c-fdcb-a46a-a9c4-f14fa1267e9d} - {d9e7621a-f41f-4c9a-a64a-bcdfc882cdd9} - C:\Windows\system32\vfzkdb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: In Windows Live Writer in &Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resou…NPUpldde-de.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD44/JSCDL/jdk/6u…ows-i586-jc.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O20 - AppInit_DLLs: vfzkdb.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll
O20 - Winlogon Notify: klogon - C:\Windows\system32\klogon.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Kaspersky Anti-Virus (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" -r (file missing)
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
Hello

Download OTScanIt2.exe to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt2 on your desktop.
  • Open the OTScanIt2 folder and double-click on OTScanIt.exe to start the program.
  • Under File Age at the top, change it from 30 days to 90 days
  • Under Additional Scans check the boxes beside Reg - App Paths, Reg - Desktop Components, Reg - Disabled MS Config Items, Reg - File Associations, File - Lop Check, File - Purity Scan, and Evnt - EventViewer Logs ( Last 10 Errors).
  • Under Rootkit Search change it to Yes
  • Check the box at the top-left beside Scan All Users
  • Now click the Run Scan button on the toolbar.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Use the Add Reply button and post the information back here in an attachment. I will review it when it comes in. The last line is < End of Report >, so make sure that is the last line in the attached report.


Make sure you attach the report in your reply. If it is too big to upload, then zip the text file and upload it that way
Okay, I hope a *.rar file works too. Thank you very much for your help and your clear insturctions! :thumbup: *edit* I want to mention that kaspersky was reporting otscanit2 as malware during the scan. I hope this did not have an effect on the scan result.
okay, here is the zip. I hope this time the file is available for you. Can't see the rar-file attached to my earlier post. It said that the upload was successful… anyway: Perhaps you can see/download the zip file attached to this post. :unsure:

Attachments:

  • [attachment removed: OTScanIt.zip]
Hello

Start OTScanIt2. Copy/Paste the information in the quotebox below into the panel where it says "Paste fix here" and then click the Run Fix button.

[Kill Explorer]
[Unregister Dlls]
[Processes - Safe List]
YY -> wininit.exe -> %SystemRoot%\System32\wininit.exe
YY -> lsm.exe -> %SystemRoot%\System32\lsm.exe
[Registry - Safe List]
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YN -> {47AA614C-73EF-4A3F-95C3-9722EEEEFC59} [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> {622A9D44-CB10-4619-B081-B6EF08000D74} [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> {7523E09B-A424-4D43-9D65-E930D06855BF} [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> {7604A914-4D06-43C9-B167-26921EBD0C41} [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> {794DAF00-83AA-4AE5-9E20-D39EFA1588ED} [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> {90D93A9E-25B2-4F84-8333-FCD2F11F6A19} [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> {938F9DCE-F7E6-4345-BD77-3395674751EE} [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YY -> {972EFC7D-6CFF-4D23-81CE-8C003B8B870D} [HKLM] -> %SystemRoot%\System32\wVPFyXNg.dll [Reg Error: Value does not exist or could not be read.]
YN -> {AF2A34BC-8EC9-426A-BE33-3D50A1939B34} [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> {D26DD9BA-554A-4620-B37F-D5C0CA9C6803} [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YY -> {D6A5C38C-A954-4207-9FED-184BCB29C8FE} [HKLM] -> %SystemRoot%\System32\tuvSjHXO.dll [Reg Error: Value does not exist or could not be read.]
YY -> {d9e7621a-f41f-4c9a-a64a-bcdfc882cdd9} [HKLM] -> %SystemRoot%\System32\vfzkdb.dll [Reg Error: Value does not exist or could not be read.]
< AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
*AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls
YY -> vfzkdb.dll -> %SystemRoot%\System32\vfzkdb.dll
< AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
< ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
YY -> "{D6A5C38C-A954-4207-9FED-184BCB29C8FE}" [HKLM] -> %SystemRoot%\System32\tuvSjHXO.dll []
< LSA Authentication Packages [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages
*LSA Authentication Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages
YY -> C:\Windows\system32\wVPFyXNg -> %SystemRoot%\System32\wVPFyXNg.dll
< LSA Authentication Packages [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages
[Registry - Additional Scans - Safe List]
< Disabled MSConfig Registry Items [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\
YY -> 767f7a12 hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %SystemRoot%\System32\nrimgbmm.dll
YY -> MSServer hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %SystemRoot%\System32\tuvSjHXO.dll
[Files/Folders - Created Within 90 Days]
NY -> tuvSjHXO.dll -> %SystemRoot%\System32\tuvSjHXO.dll
NY -> vfzkdb.dll -> %SystemRoot%\System32\vfzkdb.dll
NY -> mmbgmirn.ini -> %SystemRoot%\System32\mmbgmirn.ini
NY -> rnqaupft.dll -> %SystemRoot%\System32\rnqaupft.dll
NY -> nrimgbmm.dll -> %SystemRoot%\System32\nrimgbmm.dll
NY -> tmcomm.sys -> %SystemRoot%\System32\drivers\tmcomm.sys
NY -> gNXyFPVw.ini2 -> %SystemRoot%\System32\gNXyFPVw.ini2
NY -> gNXyFPVw.ini -> %SystemRoot%\System32\gNXyFPVw.ini
NY -> rqrtCcdd.ini2 -> %SystemRoot%\System32\rqrtCcdd.ini2
NY -> rqrtCcdd.ini -> %SystemRoot%\System32\rqrtCcdd.ini
NY -> ddcCtrqr.dll -> %SystemRoot%\System32\ddcCtrqr.dll
NY -> eOXwFiOq.ini2 -> %SystemRoot%\System32\eOXwFiOq.ini2
NY -> ipcdbf.dll -> %SystemRoot%\System32\ipcdbf.dll
NY -> vkumtetv.dll -> %SystemRoot%\System32\vkumtetv.dll
NY -> xnqrvhis.dll -> %SystemRoot%\System32\xnqrvhis.dll
NY -> kitrll.dll -> %SystemRoot%\System32\kitrll.dll
NY -> ayimpbrm.dll -> %SystemRoot%\System32\ayimpbrm.dll
NY -> itaiwo.dll -> %SystemRoot%\System32\itaiwo.dll
NY -> ilrgbudb.dll -> %SystemRoot%\System32\ilrgbudb.dll
NY -> gvbmtl.dll -> %SystemRoot%\System32\gvbmtl.dll
NY -> yptwqmvc.dll -> %SystemRoot%\System32\yptwqmvc.dll
NY -> WDJmnUtv.ini2 -> %SystemRoot%\System32\WDJmnUtv.ini2
NY -> WDJmnUtv.ini -> %SystemRoot%\System32\WDJmnUtv.ini
NY -> wVPFyXNg.dll -> %SystemRoot%\System32\wVPFyXNg.dll
NY -> khfETLDT.dll -> %SystemRoot%\System32\khfETLDT.dll
[Files/Folders - Modified Within 90 Days]
NY -> lwpwer.exe -> C:\Users\PM\AppData\Local\Temp\lwpwer.exe
NY -> uninst.exe -> C:\Users\PM\AppData\Local\Temp\uninst.exe
NY -> windfr.exe -> C:\Users\PM\AppData\Local\Temp\windfr.exe
NY -> xnqrvhis.dll -> %SystemRoot%\System32\xnqrvhis.dll
NY -> vkumtetv.dll -> %SystemRoot%\System32\vkumtetv.dll
NY -> gNXyFPVw.ini -> %SystemRoot%\System32\gNXyFPVw.ini
NY -> gNXyFPVw.ini2 -> %SystemRoot%\System32\gNXyFPVw.ini2
NY -> kitrll.dll -> %SystemRoot%\System32\kitrll.dll
[Empty Temp Folders]
[Start Explorer]
[Reboot]


The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here

I will review the information when it comes back in.



Also post a new HJT log
after I rebootet my PC (OTscanit wanted me to do so) a notepad poped up… content:

Explorer killed successfully
[Processes - Safe List]
Unable to kill process wininit.exe .
File move failed. C:\Windows\System32\wininit.exe scheduled to be moved on reboot.
Unable to kill process lsm.exe .
File move failed. C:\Windows\System32\lsm.exe scheduled to be moved on reboot.
[Registry - Safe List]
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{47AA614C-73EF-4A3F-95C3-9722EEEEFC59}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{47AA614C-73EF-4A3F-95C3-9722EEEEFC59}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{622A9D44-CB10-4619-B081-B6EF08000D74}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{622A9D44-CB10-4619-B081-B6EF08000D74}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7523E09B-A424-4D43-9D65-E930D06855BF}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7523E09B-A424-4D43-9D65-E930D06855BF}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7604A914-4D06-43C9-B167-26921EBD0C41}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7604A914-4D06-43C9-B167-26921EBD0C41}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{794DAF00-83AA-4AE5-9E20-D39EFA1588ED}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{794DAF00-83AA-4AE5-9E20-D39EFA1588ED}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{90D93A9E-25B2-4F84-8333-FCD2F11F6A19}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{90D93A9E-25B2-4F84-8333-FCD2F11F6A19}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{938F9DCE-F7E6-4345-BD77-3395674751EE}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{938F9DCE-F7E6-4345-BD77-3395674751EE}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{972EFC7D-6CFF-4D23-81CE-8C003B8B870D}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{972EFC7D-6CFF-4D23-81CE-8C003B8B870D}\ deleted successfully.
DllUnregisterServer procedure not found in C:\Windows\System32\wVPFyXNg.dll
C:\Windows\System32\wVPFyXNg.dll NOT unregistered.
C:\Windows\System32\wVPFyXNg.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF2A34BC-8EC9-426A-BE33-3D50A1939B34}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AF2A34BC-8EC9-426A-BE33-3D50A1939B34}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D26DD9BA-554A-4620-B37F-D5C0CA9C6803}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D26DD9BA-554A-4620-B37F-D5C0CA9C6803}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D6A5C38C-A954-4207-9FED-184BCB29C8FE}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D6A5C38C-A954-4207-9FED-184BCB29C8FE}\ deleted successfully.
DllUnregisterServer procedure not found in C:\Windows\System32\tuvSjHXO.dll
C:\Windows\System32\tuvSjHXO.dll NOT unregistered.
C:\Windows\System32\tuvSjHXO.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d9e7621a-f41f-4c9a-a64a-bcdfc882cdd9}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d9e7621a-f41f-4c9a-a64a-bcdfc882cdd9}\ deleted successfully.
DllUnregisterServer procedure not found in C:\Windows\System32\vfzkdb.dll
C:\Windows\System32\vfzkdb.dll NOT unregistered.
C:\Windows\System32\vfzkdb.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:vfzkdb.dll deleted successfully.
File C:\Windows\System32\vfzkdb.dll not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{D6A5C38C-A954-4207-9FED-184BCB29C8FE} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D6A5C38C-A954-4207-9FED-184BCB29C8FE}\ not found.
File C:\Windows\System32\tuvSjHXO.dll not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages:C:\Windows\system32\wVPFyXNg deleted successfully.
File C:\Windows\System32\wVPFyXNg.dll not found.
[Registry - Additional Scans - Safe List]
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\767f7a12 hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ not found.
File not found.
DllUnregisterServer procedure not found in C:\Windows\System32\nrimgbmm.dll
C:\Windows\System32\nrimgbmm.dll NOT unregistered.
C:\Windows\System32\nrimgbmm.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MSServer hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ not found.
File not found.
File C:\Windows\System32\tuvSjHXO.dll not found.
[Files/Folders - Created Within 90 Days]
File C:\Windows\System32\tuvSjHXO.dll not found!
File C:\Windows\System32\vfzkdb.dll not found!
C:\Windows\System32\mmbgmirn.ini moved successfully.
DllUnregisterServer procedure not found in C:\Windows\System32\rnqaupft.dll
C:\Windows\System32\rnqaupft.dll NOT unregistered.
C:\Windows\System32\rnqaupft.dll moved successfully.
File C:\Windows\System32\nrimgbmm.dll not found!
C:\Windows\System32\drivers\tmcomm.sys moved successfully.
C:\Windows\System32\gNXyFPVw.ini2 moved successfully.
C:\Windows\System32\gNXyFPVw.ini moved successfully.
C:\Windows\System32\rqrtCcdd.ini2 moved successfully.
C:\Windows\System32\rqrtCcdd.ini moved successfully.
DllUnregisterServer procedure not found in C:\Windows\System32\ddcCtrqr.dll
C:\Windows\System32\ddcCtrqr.dll NOT unregistered.
C:\Windows\System32\ddcCtrqr.dll moved successfully.
C:\Windows\System32\eOXwFiOq.ini2 moved successfully.
DllUnregisterServer procedure not found in C:\Windows\System32\ipcdbf.dll
C:\Windows\System32\ipcdbf.dll NOT unregistered.
C:\Windows\System32\ipcdbf.dll moved successfully.
DllUnregisterServer procedure not found in C:\Windows\System32\vkumtetv.dll
C:\Windows\System32\vkumtetv.dll NOT unregistered.
C:\Windows\System32\vkumtetv.dll moved successfully.
DllUnregisterServer procedure not found in C:\Windows\System32\xnqrvhis.dll
C:\Windows\System32\xnqrvhis.dll NOT unregistered.
C:\Windows\System32\xnqrvhis.dll moved successfully.
DllUnregisterServer procedure not found in C:\Windows\System32\kitrll.dll
C:\Windows\System32\kitrll.dll NOT unregistered.
C:\Windows\System32\kitrll.dll moved successfully.
DllUnregisterServer procedure not found in C:\Windows\System32\ayimpbrm.dll
C:\Windows\System32\ayimpbrm.dll NOT unregistered.
C:\Windows\System32\ayimpbrm.dll moved successfully.
DllUnregisterServer procedure not found in C:\Windows\System32\itaiwo.dll
C:\Windows\System32\itaiwo.dll NOT unregistered.
C:\Windows\System32\itaiwo.dll moved successfully.
DllUnregisterServer procedure not found in C:\Windows\System32\ilrgbudb.dll
C:\Windows\System32\ilrgbudb.dll NOT unregistered.
C:\Windows\System32\ilrgbudb.dll moved successfully.
DllUnregisterServer procedure not found in C:\Windows\System32\gvbmtl.dll
C:\Windows\System32\gvbmtl.dll NOT unregistered.
C:\Windows\System32\gvbmtl.dll moved successfully.
DllUnregisterServer procedure not found in C:\Windows\System32\yptwqmvc.dll
C:\Windows\System32\yptwqmvc.dll NOT unregistered.
C:\Windows\System32\yptwqmvc.dll moved successfully.
C:\Windows\System32\WDJmnUtv.ini2 moved successfully.
C:\Windows\System32\WDJmnUtv.ini moved successfully.
File C:\Windows\System32\wVPFyXNg.dll not found!
DllUnregisterServer procedure not found in C:\Windows\System32\khfETLDT.dll
C:\Windows\System32\khfETLDT.dll NOT unregistered.
C:\Windows\System32\khfETLDT.dll moved successfully.
[Files/Folders - Modified Within 90 Days]
C:\Users\PM\AppData\Local\Temp\lwpwer.exe moved successfully.
C:\Users\PM\AppData\Local\Temp\uninst.exe moved successfully.
C:\Users\PM\AppData\Local\Temp\windfr.exe moved successfully.
File C:\Windows\System32\xnqrvhis.dll not found!
File C:\Windows\System32\vkumtetv.dll not found!
File C:\Windows\System32\gNXyFPVw.ini not found!
File C:\Windows\System32\gNXyFPVw.ini2 not found!
File C:\Windows\System32\kitrll.dll not found!
[Empty Temp Folders]
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
RecycleBin -> emptied.
Explorer started successfully
< End of fix log >
OTScanIt2 by OldTimer - Version 1.0.0.15b fix logfile created on 10172008_233250

Files moved on Reboot…
File move failed. C:\Windows\System32\wininit.exe scheduled to be moved on reboot.
File move failed. C:\Windows\System32\lsm.exe scheduled to be moved on reboot.



kaspersky is troubleshooting right now, reporting about malware located here: C:\_OTScanIt\MovedFiles\10172008_233250\C_WINDOWS\System32 <— good thing, isnt't it? :wavey:

hijackthis log file:

Logfile of HijackThis v1.99.1
Scan saved at 23:38:56, on 17.10.2008
Platform: Unknown Windows (WinNT 6.00.1905 SP1)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\notepad.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\conime.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {972EFC7D-6CFF-4D23-81CE-8C003B8B870D} - C:\Windows\system32\wVPFyXNg.dll (file missing)
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKLM\..\Run: [767f7a12] rundll32.exe "C:\Windows\system32\gmfwmawb.dll",b
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: In Windows Live Writer in &Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resou…NPUpldde-de.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD44/JSCDL/jdk/6u…ows-i586-jc.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll
O20 - Winlogon Notify: klogon - C:\Windows\system32\klogon.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Kaspersky Anti-Virus (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" -r (file missing)
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)



-> No pop ups in IE right now! You are my hero! :notworthy: :woot:
Hello

  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<info.txt (<
log.txt

Logfile of random's system information tool 1.04 (written by random/random)
Run by [removed] at 2008-10-18 20:06:17
Microsoft® Windows Vista™ Home Premium Service Pack 1
System drive C: has 14 GB (7%) free of 191 GB
Total RAM: 3582 MB (70% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:06:26, on 18.10.2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\conime.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\PM\Desktop\RSIT.exe
C:\Windows\system32\rundll32.exe
C:\Program Files\trend micro\PM.exe
C:\Windows\system32\rundll32.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {972EFC7D-6CFF-4D23-81CE-8C003B8B870D} - C:\Windows\system32\wVPFyXNg.dll (file missing)
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKLM\..\Run: [767f7a12] rundll32.exe "C:\Windows\system32\gmfwmawb.dll",b
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: In Windows Live Writer in &Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resou…NPUpldde-de.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD44/JSCDL/jdk/6u…ows-i586-jc.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

–
End of file - 6490 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Auf Updates für Windows Live Toolbar prüfen.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}]
IEVkbdBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll [2008-07-29 62728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Anmelde-Hilfsprogramm - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2007-09-20 328752]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{972EFC7D-6CFF-4D23-81CE-8C003B8B870D}]
C:\Windows\system32\wVPFyXNg.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live Toolbar\msntb.dll [2007-10-19 546320]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - Windows Live Toolbar - C:\Program Files\Windows Live Toolbar\msntb.dll [2007-10-19 546320]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-08-12 6265376]
"AVP"=C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe [2008-07-29 206088]
"767f7a12"=C:\Windows\system32\gmfwmawb.dll [2008-10-17 76416]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-01-19 1233920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\767f7a12]
C:\Windows\system32\nrimgbmm.dll []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe [2007-02-28 2321600]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe [2008-09-09 89024]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CJIMETIPSYNC]
C:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\CHANGJIE\CINTLCFG.EXE [2007-03-22 66400]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe [2006-09-28 57344]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
C:\Program Files\DAEMON Tools\daemon.exe [2007-08-16 167368]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [2008-06-24 1840424]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSServer]
C:\Windows\system32\tuvSjHXO.dll []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2008-06-08 2221352]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Start WingMan Profiler]
C:\Program Files\Logitech\Gaming Software\LWEMon.exe [2008-04-04 88584]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2006-11-10 90112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsWelcomeCenter]
C:\Windows\system32\oobefldr.dll [2008-01-19 2153472]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^BDARemote.lnk]
C:\PROGRA~1\USBTV~1\UNINST~1\EM28XX\BDAREM~1.EXE [2007-03-26 77985]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
C:\Windows\system32\klogon.dll [2008-07-29 218376]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
C:\Windows\system32\wVPFyXNg

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{88c311e4-5ddc-11dd-99fd-806e6f6e6963}]
shell\AutoRun\command - E:\autoplay.exe


======List of files/folders created in the last 1 months======

2008-10-18 20:06:17 —-D—- C:\rsit
2008-10-18 20:06:17 —-D—- C:\Program Files\trend micro
2008-10-17 23:32:50 —-D—- C:\_OTScanIt
2008-10-17 21:56:49 —-A—- C:\Windows\system32\ialjur.dll
2008-10-17 21:56:43 —-A—- C:\Windows\system32\hhmugrgi.dll
2008-10-17 21:53:49 —-SH—- C:\Windows\system32\bwamwfmg.ini
2008-10-17 21:53:44 —-A—- C:\Windows\system32\gmfwmawb.dll
2008-10-16 21:25:46 —-D—- C:\Program Files\Hijackthis
2008-10-16 16:53:38 —-D—- C:\Program Files\Kaspersky Lab
2008-10-16 16:53:37 —-D—- C:\ProgramData\Kaspersky Lab
2008-10-16 16:50:46 —-D—- C:\Users\PM\AppData\Roaming\Kaspersky_Key_Finder_(KKF
2008-10-16 16:43:48 —-D—- C:\ProgramData\Kaspersky Lab Setup Files
2008-10-14 10:11:05 —-D—- C:\Program Files\CCleaner
2008-10-13 22:36:49 —-D—- C:\ProgramData\Lavasoft
2008-10-13 22:36:49 —-D—- C:\Program Files\Lavasoft
2008-10-13 22:36:00 —-D—- C:\Program Files\Common Files\Wise Installation Wizard
2008-10-13 16:24:36 —-A—- C:\Windows\system32\7d5cbe6c-.txt
2008-10-12 00:38:12 —-A—- C:\Windows\War3Unin.exe
2008-10-12 00:35:45 —-D—- C:\Program Files\Warcraft III
2008-10-10 19:29:33 —-D—- C:\Program Files\Paradox Entertainment
2008-10-09 13:13:25 —-D—- C:\Program Files\sixteen tons entertainment
2008-10-09 13:12:43 —-A—- C:\Windows\patchw32.dll
2008-10-09 13:07:57 —-D—- C:\Program Files\Lionhead Studios Ltd
2008-10-09 12:36:30 —-D—- C:\Program Files\Atari
2008-10-09 12:36:19 —-A—- C:\Windows\IsUn0407.exe
2008-10-09 12:04:53 —-D—- C:\Program Files\Common Files\Microsoft Games
2008-10-08 19:32:58 —-D—- C:\Program Files\SUNFLOWERS
2008-10-04 21:25:31 —-D—- C:\Program Files\DVDCoverPrint
2008-10-04 21:25:31 —-A—- C:\Windows\system32\picn20.dll
2008-10-04 21:25:31 —-A—- C:\Windows\system32\fxtls532.dll
2008-10-04 21:25:31 —-A—- C:\Windows\system32\Eztwain3.dll
2008-10-04 21:25:31 —-A—- C:\Windows\system32\EZTiff.dll
2008-10-04 21:25:31 —-A—- C:\Windows\system32\EZPng.dll
2008-10-04 21:25:31 —-A—- C:\Windows\system32\EZPdf.dll
2008-10-04 21:25:31 —-A—- C:\Windows\system32\EZJpeg.dll
2008-10-04 21:25:31 —-A—- C:\Windows\system32\EZGif.dll
2008-10-04 21:25:31 —-A—- C:\Windows\system32\Btn32d20.dll
2008-10-04 21:25:30 —-A—- C:\Windows\system32\UNWISE.EXE
2008-10-04 21:25:30 —-A—- C:\Windows\system32\PolarZIPLight.dll
2008-09-26 11:50:43 —-D—- C:\ProgramData\Conceiva
2008-09-26 11:44:19 —-D—- C:\Users\PM\AppData\Roaming\Conceiva
2008-09-26 11:44:19 —-A—- C:\Windows\DownloadStudioScheduleMonitor.INI
2008-09-26 11:42:43 —-D—- C:\Program Files\WinPcap
2008-09-26 11:42:01 —-D—- C:\Program Files\Conceiva
2008-09-23 20:22:29 —-D—- C:\Users\PM\AppData\Roaming\SlySoft
2008-09-23 19:38:13 —-D—- C:\Program Files\Plato Video To iPod Converter
2008-09-23 19:38:13 —-A—- C:\Windows\system32\viscomwave.dll
2008-09-23 19:38:13 —-A—- C:\Windows\system32\viscomqtde.dll
2008-09-23 17:43:53 —-D—- C:\ProgramData\vsosdk
2008-09-23 17:32:22 —-D—- C:\ProgramData\SlySoft
2008-09-23 16:29:08 —-D—- C:\MAGICDVDCOPY_TEMP
2008-09-23 16:26:02 —-D—- C:\Users\PM\AppData\Roaming\Vso
2008-09-23 16:26:02 —-A—- C:\Users\PM\AppData\Roaming\inst.exe
2008-09-23 16:26:00 —-D—- C:\Program Files\DVDFab 5
2008-09-23 15:36:59 —-D—- C:\Program Files\Total Video Converter
2008-09-23 03:22:48 —-D—- C:\Program Files\danny_kay1710
2008-09-23 03:12:16 —-D—- C:\Program Files\Red Kawa
2008-09-23 00:34:52 —-ASH—- C:\Windows\SFC8E217B.tmp
2008-09-23 00:33:17 —-D—- C:\Program Files\SlySoft

======List of files/folders modified in the last 1 months======

2008-10-18 20:06:26 —-D—- C:\Windows\Prefetch
2008-10-18 20:06:21 —-D—- C:\Windows\Temp
2008-10-18 20:06:17 —-RD—- C:\Program Files
2008-10-18 20:03:25 —-D—- C:\Users\PM\AppData\Roaming\uTorrent
2008-10-18 13:49:32 —-A—- C:\Windows\NeroDigital.ini
2008-10-18 11:44:03 —-D—- C:\Windows\System32
2008-10-18 11:44:03 —-D—- C:\Windows\inf
2008-10-18 11:44:03 —-A—- C:\Windows\system32\PerfStringBackup.INI
2008-10-18 00:47:54 —-SHD—- C:\System Volume Information
2008-10-17 23:32:51 —-D—- C:\Windows\system32\drivers
2008-10-17 22:39:38 —-D—- C:\Program Files\Steam
2008-10-16 21:08:16 —-SD—- C:\Users\PM\AppData\Roaming\Microsoft
2008-10-16 17:35:47 —-AD—- C:\Windows
2008-10-16 17:02:13 —-D—- C:\Windows\system32\WDI
2008-10-16 16:55:14 —-SHD—- C:\Windows\Installer
2008-10-16 16:54:11 —-D—- C:\Windows\system32\catroot
2008-10-16 16:53:45 —-HD—- C:\ProgramData
2008-10-16 16:50:10 —-D—- C:\Windows\system32\catroot2
2008-10-16 16:48:15 —-D—- C:\ProgramData\Avira
2008-10-16 09:36:46 —-D—- C:\Program Files\Internet Explorer
2008-10-16 08:53:00 —-AD—- C:\ProgramData\TEMP
2008-10-14 21:45:51 —-D—- C:\Program Files\Tumblebugs 2
2008-10-14 10:12:39 —-D—- C:\Windows\Minidump
2008-10-14 10:12:39 —-D—- C:\Windows\Debug
2008-10-13 22:36:00 —-D—- C:\Program Files\Common Files
2008-10-13 14:26:13 —-D—- C:\Program Files\Common Files\Steam
2008-10-13 14:23:43 —-HD—- C:\Program Files\InstallShield Installation Information
2008-10-13 13:17:02 —-D—- C:\Users\PM\AppData\Roaming\mIRC
2008-10-13 13:06:33 —-D—- C:\Program Files\mIRC
2008-10-12 18:25:14 —-D—- C:\Users\PM\AppData\Roaming\Teleca
2008-10-12 18:25:07 —-D—- C:\Program Files\Common Files\Teleca Shared
2008-10-12 18:18:21 —-D—- C:\Program Files\PopCap Games
2008-10-11 23:48:44 —-D—- C:\Windows\system32\NDF
2008-10-11 12:38:10 —-D—- C:\Windows\system32\LogFiles
2008-10-09 12:55:32 —-D—- C:\Program Files\Common Files\InstallShield
2008-10-09 12:20:53 —-RSD—- C:\Windows\assembly
2008-10-09 12:04:32 —-SD—- C:\ProgramData\Microsoft
2008-10-09 12:04:16 —-D—- C:\Windows\winsxs
2008-10-09 11:52:16 —-RSD—- C:\Windows\Fonts
2008-10-09 11:44:00 —-D—- C:\Program Files\Microsoft Games
2008-10-08 12:55:29 —-D—- C:\Users\PM\AppData\Roaming\Adobe
2008-09-28 12:16:49 —-D—- C:\Downloads
2008-09-28 10:51:25 —-D—- C:\Program Files\SpeedFan
2008-09-27 12:12:21 —-D—- C:\Program Files\uTorrent
2008-09-26 16:27:52 —-D—- C:\Windows\system32\Tasks
2008-09-23 18:34:07 —-D—- C:\Users\PM\AppData\Roaming\dvdcss

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2008-07-21 24392]
R1 kl1;kl1; C:\Windows\system32\DRIVERS\kl1.sys [2008-07-21 121872]
R1 KLIF;Kaspersky Lab Driver; C:\Windows\system32\DRIVERS\klif.sys [2008-10-16 216080]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter; C:\Windows\system32\DRIVERS\klim6.sys [2008-07-09 20496]
R3 AnyDVD;AnyDVD; C:\Windows\System32\Drivers\AnyDVD.sys [2008-09-04 99648]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2008-01-10 3483648]
R3 ElbyCDFL;ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [2007-02-16 34760]
R3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-08-12 2159384]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2008-09-23 47360]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2006-11-02 44544]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\Windows\system32\drivers\WmBEnum.sys [2008-01-24 19336]
R3 WmXlCore;Logitech Translation Layer Driver; C:\Windows\system32\drivers\WmXlCore.sys [2008-01-24 48904]
S3 ar9p5cot;ar9p5cot; C:\Windows\system32\drivers\ar9p5cot.sys []
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
S3 NPF;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2007-11-06 34064]
S3 s115bus;Sony Ericsson Device 115 driver (WDM); C:\Windows\system32\DRIVERS\s115bus.sys [2007-04-23 83208]
S3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s115mdfl.sys [2007-04-23 15112]
S3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s115mdm.sys [2007-04-23 108680]
S3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s115mgmt.sys [2007-04-23 100488]
S3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s115obex.sys [2007-04-23 98568]
S3 s616bus;Sony Ericsson Device 616 driver (WDM); C:\Windows\system32\DRIVERS\s616bus.sys [2007-04-03 83208]
S3 s616mdfl;Sony Ericsson Device 616 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s616mdfl.sys [2007-04-03 15112]
S3 s616mdm;Sony Ericsson Device 616 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s616mdm.sys [2007-04-03 108680]
S3 s616mgmt;Sony Ericsson Device 616 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s616mgmt.sys [2007-04-03 100360]
S3 s616nd5;Sony Ericsson Device 616 USB Ethernet Emulation SEMC616 (NDIS); C:\Windows\system32\DRIVERS\s616nd5.sys [2007-04-03 23176]
S3 s616obex;Sony Ericsson Device 616 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s616obex.sys [2007-04-03 98568]
S3 s616unic;Sony Ericsson Device 616 USB Ethernet Emulation SEMC616 (WDM); C:\Windows\system32\DRIVERS\s616unic.sys [2007-04-03 99080]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-19 35328]
S3 WmFilter;Logitech Gaming HID Filter Driver; C:\Windows\system32\drivers\WmFilter.sys [2008-01-24 28168]
S3 WmVirHid;Logitech Virtual Hid Device Driver; C:\Windows\system32\drivers\WmVirHid.sys [2008-01-24 14728]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2006-11-02 39936]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-10-13 611664]
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2008-01-10 643072]
R2 AVP;Kaspersky Anti-Virus; C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe [2008-07-29 206088]
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2008-06-08 877864]
R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\Windows\system32\IoctlSvc.exe [2006-12-19 81920]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2008-08-23 654848]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2008-06-24 537896]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files\WinPcap\rpcapd.exe [2007-11-06 92792]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2008-10-13 87288]
S3 usnjsvc;Messenger USN Journal Reader-Service für freigegebene Ordner; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]

—————–EOF—————–


info.txt

info.txt logfile of random's system information tool 1.04 2008-10-18 20:06:28

======Uninstall list======

–>C:\Program Files\Nero\Nero8\\nero\uninstall\UNNERO.exe /UNINSTALL
–>C:\Windows\UNNeroBackItUp.exe /UNINSTALL
–>C:\Windows\UNNeroMediaHome.exe /UNINSTALL
–>C:\Windows\UNNeroShowTime.exe /UNINSTALL
–>C:\Windows\UNNeroVision.exe /UNINSTALL
–>C:\Windows\UNRecode.exe /UNINSTALL
Ad-Aware–>MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe Anchor Service CS3–>MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
Adobe Asset Services CS3–>MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
Adobe Bridge CS3–>MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}
Adobe Bridge Start Meeting–>MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}
Adobe Camera Raw 4.0–>MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
Adobe CMaps–>MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
Adobe Color - Photoshop Specific–>MsiExec.exe /I{A2D81E70-2A98-4A08-A628-94388B063C5E}
Adobe Color Common Settings–>MsiExec.exe /I{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}
Adobe Color EU Extra Settings–>MsiExec.exe /I{51846830-E7B2-4218-8968-B77F0FF475B8}
Adobe Color JA Extra Settings–>MsiExec.exe /I{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}
Adobe Color NA Recommended Settings–>MsiExec.exe /I{95655ED4-7CA5-46DF-907F-7144877A32E5}
Adobe Default Language CS3–>MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}
Adobe Device Central CS3–>MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
Adobe ExtendScript Toolkit 2–>C:\Program Files\Common Files\Adobe\Installers\3e054d2218e7aa282c2369d939e58ff\Setup.exe
Adobe ExtendScript Toolkit 2–>MsiExec.exe /I{24D7346D-D4B4-45E8-98EA-75EC14B42DD8}
Adobe Flash Player ActiveX–>C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Fonts All–>MsiExec.exe /I{6ABE0BEE-D572-4FE8-B434-9E72A289431B}
Adobe Help Viewer CS3–>MsiExec.exe /I{04AF207D-9A77-465A-8B76-991F6AB66245}
Adobe Linguistics CS3–>MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}
Adobe PDF Library Files–>MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
Adobe Photoshop CS3–>C:\Program Files\Common Files\Adobe\Installers\719d6f144d0c086a0dfa7ff76bb9ac1\Setup.exe
Adobe Photoshop CS3–>MsiExec.exe /I{3D7E3EC9-46CF-4359-9289-39CE01DFB82F}
Adobe Reader 9 - Deutsch–>MsiExec.exe /I{AC76BA86-7AD7-1031-7B44-A90000000001}
Adobe Setup–>MsiExec.exe /I{B3C02EC1-A7B0-4987-9A43-8789426AAA7D}
Adobe Setup–>MsiExec.exe /I{FF11004C-F42A-4A31-9BCF-7F5C8FDBE53C}
Adobe Stock Photos CS3–>MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183}
Adobe Type Support–>MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}
Adobe Update Manager CS3–>MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}
Adobe Version Cue CS3 Client–>MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}
Adobe WinSoft Linguistics Plugin–>MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
Adobe XMP Panels CS3–>MsiExec.exe /I{802771A9-A856-4A41-ACF7-1450E523C923}
AnyDVD–>"C:\Program Files\SlySoft\AnyDVD\AnyDVD-uninst.exe" /D="C:\Program Files\SlySoft\AnyDVD"
ATI AVIVO Codecs–>MsiExec.exe /I{89DE67AD-08B8-4699-A55D-CA5C0AF82BF3}
Audacity 1.3.5–>"C:\Program Files\Audacity 1.3 Beta\unins000.exe"
Battlefield 2™–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{04858915-9F49-4B2A-AED4-DC49A7DE6A7B}\setup.exe" -l0x7 -removeonly
Big Money Deluxe 1.3–>C:\Program Files\PopCap Games\Big Money Deluxe\PopUninstall.exe "C:\Program Files\PopCap Games\Big Money Deluxe\Install.log"
CCleaner (remove only)–>"C:\Program Files\CCleaner\uninst.exe"
CloneCD–>"C:\Program Files\SlySoft\CloneCD\ccd-uninst.exe" /D="C:\Program Files\SlySoft\CloneCD"
CloneDVDmobile–>"C:\Program Files\SlySoft\CloneDVDmobile\CloneDVDmobile-uninst.exe" /D="C:\Program Files\SlySoft\CloneDVDmobile"
DEVIL MAY CRY 4–>MsiExec.exe /I{D4E5A687-797D-44B1-8F96-4FD7A24166A9}
DVD and CD Cover Print–>C:\Windows\System32\UNWISE.EXE C:\Windows\System32\INSTALL.LOG
DVDFab Platinum–>C:\Program Files\DVDFab 5\Uninstall.exe
EPSON Scan–>C:\Program Files\epson\escndv\setup\setup.exe /r
EPSON-Drucker-Software–>C:\Windows\system32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
Free CD to MP3 Converter–>C:\PROGRA~1\CDTOMP~1\UNWISE.EXE C:\PROGRA~1\CDTOMP~1\INSTALL.LOG
Google Earth Pro–>MsiExec.exe /X{29622F4A-245C-4126-8764-897E21E888D1}
Gotcha!–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{68D97286-D1C7-445C-8007-4778CB874D08}\Setup.exe" -l0x7
Hervorhebe-Funktion (Windows Live Toolbar)–>MsiExec.exe /X{00D0200F-3B4D-4A2F-869E-533ED835A943}
Hijackthis 1.99.1–>"C:\Program Files\Hijackthis\unins000.exe"
HijackThis 2.0.2–>"C:\Program Files\trend micro\HijackThis.exe" /uninstall
HLSW v1.2.1–>"C:\Program Files\HLSW\unins000.exe"
Java™ 6 Update 7–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Kaspersky Anti-Virus 2009–>MsiExec.exe /I{6580C5A3-2336-4EC5-85F1-3448C5F6208A}
Kaspersky Anti-Virus 2009–>MsiExec.exe /I{6580C5A3-2336-4EC5-85F1-3448C5F6208A}
Logitech Gaming Software 5.02–>MsiExec.exe /X{64B20B36-AEE7-4DD4-897C-C5DA5C218F60}
Microsoft Flight Simulator X–>C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{F535B2CF-C9BB-4162-B03A-02D6971F32CC}
Microsoft Office 2003 Proofing Tools–>MsiExec.exe /I{901F0409-6000-11D3-8CFE-0150048383C9}
Microsoft Office Professional Edition 2003–>MsiExec.exe /I{90110407-6000-11D3-8CFE-0150048383C9}
Microsoft SQL Server 2005 Compact Edition [ENU]–>MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft Visual C++ 2005 Redistributable–>MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022–>MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
MSXML 4.0 SP2 (KB936181)–>MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB941833)–>MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
MSXML 4.0 SP2 Parser und SDK–>MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
Mumble and Murmur–>C:\Program Files\Mumble\Uninstall.exe
Nero 8–>MsiExec.exe /X{6D45EF03-E8EE-4355-81C3-F918CBCF1031}
neroxml–>MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
NJStar Chinese WP–>C:\Program Files\NJStar Chinese WP\uninst.exe
PDF Settings–>MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
Plato Video To iPod Converter 5.94–>"C:\Program Files\Plato Video To iPod Converter\unins000.exe"
Pong–>C:\Windows\IsUn0407.exe -f"C:\Program Files\Atari\Pong\Uninst.isu"
PSP ISO Compressor–>MsiExec.exe /X{D47087E7-AA15-4D1D-8C0A-60F7E446D597}
Realtek High Definition Audio Driver–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -removeonly
Smart Menus (Windows Live Toolbar)–>MsiExec.exe /X{2DD6C198-FA9A-40B4-8DE5-CE5206E3EB34}
SpeedFan (remove only)–>"C:\Program Files\SpeedFan\uninstall.exe"
TechnoMage–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{18C018C3-452F-41FD-BABE-4568A953C036}\setup.exe" -l0x7
Total Video Converter 3.12 080307–>"C:\Program Files\Total Video Converter\unins000.exe"
USB Video Device Driver–>C:\Program Files\InstallShield Installation Information\{2758691A-2CDE-4942-A4AC-0E8F61FE2067}\setup.exe -runfromtemp -l0x0007 -removeonly
VCRedistSetup–>MsiExec.exe /I{3921A67A-5AB1-4E48-9444-C71814CF3027}
Warcraft III–>C:\Windows\War3Unin.exe C:\Windows\War3Unin.dat
Windows Live Anmelde-Assistent–>MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
Windows Live Favorites für Windows Live Toolbar–>MsiExec.exe /X{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}
Windows Live Fotogalerie–>MsiExec.exe /X{A1D08B90-AE1A-4885-AC29-731496FD397E}
Windows Live installer–>MsiExec.exe /X{7A7B0BF3-2F00-4F03-8A9B-6ABCC07B90C6}
Windows Live Mail–>MsiExec.exe /I{82F2B38B-1426-443D-874C-AC25675E7BEB}
Windows Live Messenger–>MsiExec.exe /X{2B091530-69AA-442E-AB09-39ED06B58220}
Windows Live Toolbar–>"C:\Program Files\Windows Live Toolbar\UnInstall.exe" {0AC49543-9CE2-4434-AD42-5AA6E2967FA5}
Windows Live Toolbar–>MsiExec.exe /X{0AC49543-9CE2-4434-AD42-5AA6E2967FA5}
Windows Live Toolbar-Erweiterung (Windows Live Toolbar)–>MsiExec.exe /X{218761F6-CBF6-4973-B910-A33E6563A1EA}
Windows Live Writer–>MsiExec.exe /X{B8D42C3A-3CFF-4A8A-A7DA-4F44474D12C5}
WinPcap 4.0.2–>C:\Program Files\WinPcap\uninstall.exe
WinRAR–>C:\Program Files\WinRAR\uninstall.exe

======Hosts File======

127.0.0.1 localhost
127.0.0.1 update.microsoft.com
127.0.0.1 www.windowsupdate.microsoft.com
127.0.0.1 avpg.crsi.symantec.com
127.0.0.1 pif.symantec.com
127.0.0.1 pifmain.symantec.com
127.0.0.1 update.avg.com
127.0.0.1 backup.avg.cz
127.0.0.1 akamai.avg.com
127.0.0.1 u20.eset.com

======Security center information======

AV: Avira AntiVir PersonalEdition
AV: Kaspersky Anti-Virus
AS: Windows Defender (disabled)
AS: Kaspersky Anti-Virus

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=C:\Program Files\Internet Explorer;;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files\Common Files\Nero\Lib\;C:\Program Files\Common Files\Nero\Lib\;C:\Program Files\Common Files\Nero\Lib\;C:\Program Files\Common Files\Teleca Shared
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 11, GenuineIntel
"PROCESSOR_REVISION"=0f0b
"NUMBER_OF_PROCESSORS"=2

—————–EOF—————–
You have two anti-virus programs, you need to remove one of these

AV: Avira AntiVir PersonalEdition
AV: Kaspersky Anti-Virus



1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below(if present):

O2 - BHO: (no name) - {972EFC7D-6CFF-4D23-81CE-8C003B8B870D} - C:\Windows\system32\wVPFyXNg.dll (file missing)
O4 - HKLM\..\Run: [767f7a12] rundll32.exe "C:\Windows\system32\gmfwmawb.dll",b


2. Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.



Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    ar9p5cot
    
    :Reg
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\767f7a12]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSServer]
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
    "authentication packages"=msv1_0
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{88c311e4-5ddc-11dd-99fd-806e6f6e6963}]
    
    :Files
    C:\Windows\system32\ialjur.dll
    C:\Windows\system32\hhmugrgi.dll
    C:\Windows\system32\bwamwfmg.ini
    C:\Windows\system32\gmfwmawb.dll
    C:\Windows\system32\7d5cbe6c-.txt
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.



Also post a new Rsit log

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI