This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] periodic call of rundll32.exe

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hello,
can't find the beast and would appreciate your help.
Pleas excuse my poor English. Thanks very much in advance.

The system:
XP32 in a virtual machine (VMware WS 6.05)

The problem:

1. a permanent periodic call of rundll32.exe
2. repeated virus/trojan-detection by AVG Free-Edition (virus Hare.7786.BOOT, trojan horse Generic11.BEOG, Trojan horde BackDoor.Generic10.TDZ). No change in behavior after removing/healing
3. actual no error detected.

What I did till now:

Followed the Instructions of "self Help before Posting"

Logfile of HijackThis v1.99.1
Scan saved at 20:56:36, on 24.10.2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
D:\PROGRA~1\AVG\avgwdsvc.exe
C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7Debug\mdm.exe
C:\Programme\VMware\VMware Tools\VMwareService.exe
D:\PROGRA~1\AVG\avgrsx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Programme\VMware\VMware Tools\VMwareTray.exe
C:\Programme\VMware\VMware Tools\VMwareUser.exe
C:\Programme\Microsoft IntelliType Pro\itype.exe
C:\Programme\Java\jre1.6.0_07\bin\jusched.exe
D:\PROGRA~1\AVG\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\NOTEPAD.EXE
D:\Programme\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\Programme\AVG\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [VMware Tools] C:\Programme\VMware\VMware Tools\VMwareTray.exe
O4 - HKLM\..\Run: [VMware User Process] C:\Programme\VMware\VMware Tools\VMwareUser.exe
O4 - HKLM\..\Run: [itype] "C:\Programme\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] D:\PROGRA~1\AVG\avgtray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Programme\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_1_0 -reboot 1
O4 - Startup: ERUNT AutoBackup.lnk = D:\Programme\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Microsoft Office.lnk = D:\Programme\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {156BF4B7-AE3A-4365-BD88-95A75AF8F09D} (HPSDDX Class) - http://www.hp.com/cpso-support-new/SDD/hpsddObjSigned.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1127916373453
O16 - DPF: {B9F79165-A264-4C4A-A211-133A5E8D647F} (F-Secure Health Check 1.1) - http://support.f-secure.com/enu/home/onlin…/fshc/fscax.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2D03C99A-732D-417A-8DE6-22957455BE63}: NameServer = 192.168.102.2
O17 - HKLM\System\CCS\Services\Tcpip\..\{2FF0DC25-E2E1-44D9-AA30-32DDF2A59C2F}: NameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{8181BE46-75A4-490F-AF63-DECE3057A7DA}: NameServer = 192.168.102.2
O17 - HKLM\System\CS1\Services\Tcpip\..\{2D03C99A-732D-417A-8DE6-22957455BE63}: NameServer = 192.168.102.2
O17 - HKLM\System\CS2\Services\Tcpip\..\{2D03C99A-732D-417A-8DE6-22957455BE63}: NameServer = 192.168.102.2
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Programme\AVG\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: TPSvc - C:\WINDOWS\SYSTEM32\TPSvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\avgwdsvc.exe
O23 - Service: AVM FRITZ!web Routing Service (de_serv) - Unknown owner - C:\Programme\Gemeinsame Dateien\AVM\de_serv.exe (file missing)
O23 - Service: start_firewall - Unknown owner - D:\Programme\VMware\_vmService\srvany.exe
O23 - Service: TP AutoConnect Service (TPAutoConnSvc) - ThinPrint GmbH - C:\Programme\VMware\VMware Tools\TPAutoConnSvc.exe
O23 - Service: VMware Tools Service (VMTools) - VMware, Inc. - C:\Programme\VMware\VMware Tools\VMwareService.exe

Malwarebytes' Anti-Malware scan detected no problems.

waiting for your answer,
Andreas
Hello and Welcome to the forum.

I'm not seeing anything bad but lets have a look.

DO NOT use any TOOLS such as Combofix, Vundofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.



Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.



Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
"copy/paste" a new HijackThis log file into this thread as well.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.


Also please describe how your computer behaves at the moment.
Hello LDTate,
thank you for your help.

At the moment the symptoms are nearly disappeared (apparently) but it's too good to last.
Yesterday there was a rundll-call once every 2 seconds, which changes the cursor-icon to the busy one.

Following the output of CF (in German - hopefully no problem for you) and HJT:

ComboFix 08-10-25.01 - yota 2008-10-26 16:03:33.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1031.18.1657 [GMT 1:00]
ausgeführt von:: C:\Dokumente und Einstellungen\yota\Desktop\ComboFix.exe
* Neuer Wiederherstellungspunkt wurde erstellt
.

((((((((((((((((((((((( Dateien erstellt von 2008-09-26 bis 2008-10-26 ))))))))))))))))))))))))))))))
.

2008-10-24 19:08 . 2008-10-24 19:08 d——– C:\Dokumente und Einstellungen\yota\Anwendungsdaten\Uniblue
2008-10-24 19:07 . 2008-10-24 19:08 d–h-c— C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2008-10-24 18:26 . 2008-10-24 18:26 d——– C:\Dokumente und Einstellungen\yota\Anwendungsdaten\Malwarebytes
2008-10-24 18:26 . 2008-10-24 18:26 d——– C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes
2008-10-24 18:26 . 2008-10-22 15:10 38,496 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-24 18:26 . 2008-10-22 15:10 15,504 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-10-24 07:28 . 2008-10-15 17:35 337,408 —–c— C:\WINDOWS\system32\dllcache\netapi32.dll
2008-10-19 17:40 . 2008-10-19 17:58 d——– C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SecTaskMan
2008-10-19 16:56 . 2008-10-19 16:58 d——– C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Spybot - Search & Destroy
2008-10-15 10:59 . 2008-09-15 16:24 1,846,528 —–c— C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-15 10:59 . 2008-09-08 11:41 333,824 —–c— C:\WINDOWS\system32\dllcache\srv.sys
2008-10-15 10:58 . 2008-08-14 14:19 2,191,488 —–c— C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-15 10:58 . 2008-08-14 14:19 2,147,840 —–c— C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-15 10:58 . 2008-08-14 14:19 2,068,352 —–c— C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-15 10:58 . 2008-08-14 14:19 2,026,496 —–c— C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-09 13:55 . 2008-10-26 15:12 d——– C:\WINDOWS\system32\drivers\Avg
2008-10-09 13:55 . 2008-10-09 13:55 d——– C:\Programme\AVG
2008-10-09 13:55 . 2008-10-11 11:37 97,928 –a—— C:\WINDOWS\system32\drivers\avgldx86.sys
2008-10-09 13:55 . 2008-10-11 11:37 10,520 –a—— C:\WINDOWS\system32\avgrsstx.dll

.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-09 12:55 ——— d—–w C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\avg8
2008-10-07 09:41 ——— d—–w C:\Programme\microsoft frontpage
2008-09-15 15:24 1,846,528 —-a-w C:\WINDOWS\system32\win32k.sys
2008-09-08 10:41 333,824 —-a-w C:\WINDOWS\system32\drivers\srv.sys
2008-09-04 16:39 ——— d—–w C:\Programme\Gemeinsame Dateien\Adobe
2008-09-04 16:27 ——— d—–w C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\WinZip
2008-08-26 07:57 826,368 —-a-w C:\WINDOWS\system32\wininet.dll
2008-08-14 13:19 2,147,840 —-a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 13:19 2,026,496 —-a-w C:\WINDOWS\system32\ntkrnlpa.exe
2007-10-12 08:47 46,320 —-a-w C:\Dokumente und Einstellungen\yota\Anwendungsdaten\GDIPFONTCACHEV1.DAT
2007-08-10 06:38 14 —-a-w C:\Dokumente und Einstellungen\yota\getfile.dat
.

(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VMware Tools"="C:\Programme\VMware\VMware Tools\VMwareTray.exe" [2008-03-04 92720]
"VMware User Process"="C:\Programme\VMware\VMware Tools\VMwareUser.exe" [2008-03-04 268848]
"itype"="C:\Programme\Microsoft IntelliType Pro\itype.exe" [2006-11-22 813912]
"SunJavaUpdateSched"="C:\Programme\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"AVG8_TRAY"="D:\PROGRA~1\AVG\avgtray.exe" [2008-10-11 1234712]
"SoundMan"="SOUNDMAN.EXE" [2003-12-19 C:\WINDOWS\SOUNDMAN.EXE]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2008-04-14 15360]

C:\Dokumente und Einstellungen\yota\Startmen\Programme\Autostart\
ERUNT AutoBackup.lnk - D:\Programme\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

C:\Dokumente und Einstellungen\All Users\Startmen\Programme\Autostart\
Microsoft Office.lnk - D:\Programme\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\TPSvc]
2008-02-15 13:50 364544 C:\WINDOWS\system32\TPSvc.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"D:\\Programme\\totalcmd\\TOTALCMD.EXE"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Dokumente und Einstellungen\\yota\\Lokale Einstellungen\\Apps\\2.0\\DYRHCO36.ZKC\\CHX5HAQY.CPD\\frit..tion_f8d772dfbb3f7453_0002.0001_0e85bc5722874a01\\fritzbox-usb-fernanschluss.exe"=
"%windir%\\system32\\sessmgr.exe"=
"D:\\Programme\\AVG\\avgupd.exe"=

R0 Fasttrak;Fasttrak;C:\WINDOWS\system32\drivers\Fasttrak.sys [2001-11-22 70528]
R0 vmscsi;vmscsi;C:\WINDOWS\system32\DRIVERS\vmscsi.sys [2008-02-15 17968]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-10-11 97928]
R2 avg8wd;AVG8 WatchDog;D:\PROGRA~1\AVG\avgwdsvc.exe [2008-10-11 231704]
R2 hgfs;hgfs;C:\WINDOWS\system32\DRIVERS\hgfs.sys [2008-03-04 102832]
R2 LGTO_Sync;Sync Driver;C:\WINDOWS\system32\Drivers\lgtosync.sys [2008-02-15 36656]
R2 VMMEMCTL;VMware server memory controller;C:\Programme\VMware\VMware Tools\Drivers\memctl\vmmemctl.sys [2008-02-15 15664]
R2 VMTools;VMware Tools Service;C:\Programme\VMware\VMware Tools\VMwareService.exe [2008-03-04 264752]
R3 vmmouse;VMware Pointing Device;C:\WINDOWS\system32\DRIVERS\vmmouse.sys [2008-02-15 11696]
R3 vmx_svga;vmx_svga;C:\WINDOWS\system32\DRIVERS\vmx_svga.sys [2008-03-04 62768]
R3 vmxnet;VMware Ethernet Adapter Driver;C:\WINDOWS\system32\DRIVERS\vmxnet.sys [2008-02-15 34992]
S3 start_firewall;start_firewall;D:\Programme\VMware\_vmService\srvany.exe [2005-10-06 8192]
S3 TPAutoConnSvc;TP AutoConnect Service;C:\Programme\VMware\VMware Tools\TPAutoConnSvc.exe [2008-02-15 294912]

*Newly Created Service* - PROCEXP90
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -

HKCU-Run-updateMgr - C:\Programme\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
Notify-AtiExtEvent - (no file)


.
——- Zusätzlicher Suchlauf ——-
.
FireFox -: Profile - C:\Dokumente und Einstellungen\yota\Anwendungsdaten\Mozilla\Firefox\Profiles\iimlduf7.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - about:blank
FF -: plugin - C:\Programme\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - D:\Programme\Adobe\Reader 9.0\Reader\browser\nppdf32.dll
FF -: plugin - D:\Programme\Mozilla Firefox\plugins\npnul32.dll
FF -: plugin - D:\Programme\Mozilla Firefox\plugins\nppdf32.dll
FF -: plugin - D:\Programme\Mozilla Firefox\plugins\NPSWF32.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-26 16:04:32
Windows 5.1.2600 Service Pack 3 NTFS

Scanne versteckte Prozesse…

Scanne versteckte Autostarteinträge…

Scanne versteckte Dateien…

Scan erfolgreich abgeschlossen
versteckte Dateien: 0

**************************************************************************
.
Zeit der Fertigstellung: 2008-10-26 16:07:17
ComboFix-quarantined-files.txt 2008-10-26 15:07:15

Vor Suchlauf: 10 Verzeichnis(se), 16.279.748.608 Bytes frei
Nach Suchlauf: 10 Verzeichnis(se), 16,273,584,128 Bytes frei

WindowsXP-KB310994-SP2-Pro-BootDisk-DEU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

124 — E O F — 2008-10-15 11:25:24


Logfile of HijackThis v1.99.1
Scan saved at 16:21:42, on 26.10.2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
D:\PROGRA~1\AVG\avgwdsvc.exe
C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7Debug\mdm.exe
C:\Programme\VMware\VMware Tools\VMwareService.exe
D:\PROGRA~1\AVG\avgrsx.exe
C:\Programme\VMware\VMware Tools\VMwareTray.exe
C:\Programme\VMware\VMware Tools\VMwareUser.exe
C:\Programme\Microsoft IntelliType Pro\itype.exe
C:\Programme\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
D:\Programme\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\Programme\AVG\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [VMware Tools] C:\Programme\VMware\VMware Tools\VMwareTray.exe
O4 - HKLM\..\Run: [VMware User Process] C:\Programme\VMware\VMware Tools\VMwareUser.exe
O4 - HKLM\..\Run: [itype] "C:\Programme\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] D:\PROGRA~1\AVG\avgtray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: ERUNT AutoBackup.lnk = D:\Programme\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Microsoft Office.lnk = D:\Programme\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {156BF4B7-AE3A-4365-BD88-95A75AF8F09D} (HPSDDX Class) - http://www.hp.com/cpso-support-new/SDD/hpsddObjSigned.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1127916373453
O16 - DPF: {B9F79165-A264-4C4A-A211-133A5E8D647F} (F-Secure Health Check 1.1) - http://support.f-secure.com/enu/home/onlin…/fshc/fscax.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2D03C99A-732D-417A-8DE6-22957455BE63}: NameServer = 192.168.102.2
O17 - HKLM\System\CCS\Services\Tcpip\..\{2FF0DC25-E2E1-44D9-AA30-32DDF2A59C2F}: NameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{8181BE46-75A4-490F-AF63-DECE3057A7DA}: NameServer = 192.168.102.2
O17 - HKLM\System\CS1\Services\Tcpip\..\{2D03C99A-732D-417A-8DE6-22957455BE63}: NameServer = 192.168.102.2
O17 - HKLM\System\CS2\Services\Tcpip\..\{2D03C99A-732D-417A-8DE6-22957455BE63}: NameServer = 192.168.102.2
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Programme\AVG\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: TPSvc - C:\WINDOWS\SYSTEM32\TPSvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\avgwdsvc.exe
O23 - Service: AVM FRITZ!web Routing Service (de_serv) - Unknown owner - C:\Programme\Gemeinsame Dateien\AVM\de_serv.exe (file missing)
O23 - Service: start_firewall - Unknown owner - D:\Programme\VMware\_vmService\srvany.exe
O23 - Service: TP AutoConnect Service (TPAutoConnSvc) - ThinPrint GmbH - C:\Programme\VMware\VMware Tools\TPAutoConnSvc.exe
O23 - Service: VMware Tools Service (VMTools) - VMware, Inc. - C:\Programme\VMware\VMware Tools\VMwareService.exe
Everything looks ok there.
We could do an online scan if you like.

Lets run an F-Secure online scan it will scan for Viruses, Spyware and RootKits:
  • Click HERE
  • Scroll to the bottom of the page and click the Start scanning button. A window will pop up.
  • Allow the Active X control to be installed on your computer, then click the Accept button
  • Click Full System Scan and allow the components to download and the scan to complete.
  • If malware is found, check Submit samples to F-Secure then select Automatic cleaning
  • When cleaning has finitished, click Show report (this will open an Internet Explorer window containing the report)
  • Highlight and Copy (CTRL + C) the complete report, and Paste (CTRL + V) in a new reply to this post
If Automatic cleaning with Submit samples hangs, click Cancel, then New Scan
  • When the cleaning option is presented, Uncheck Submit samples to F-Secure
  • Click Automatic cleaning
  • When cleaning has finitished, click Show report (this will open an Internet Explorer window containing the report)
  • Highlight and Copy (CTRL + C) the complete report, and Paste (CTRL + V) in a new reply to this post

Note: This scan will only work with Internet Explorer.
You must be logged on a administrator rights to run this scan.
The scan may take a few hours.
… as nearly expected it seems that neither F-Secure provides an explanation.
I know, I should be happy, but …


Scanning Report
Sunday, October 26, 2008 18:50:24 - 19:32:46

Computer name: VM_SPRINTER
Scanning type: Scan system for malware, rootkits
Target: C:\ D:\ E:\

Result: 0 malware found

Statistics
Scanned:

* Files: 35674
* System: 2903
* Not scanned: 6

Actions:

* Disinfected: 0
* Renamed: 0
* Deleted: 0
* None: 0
* Submitted: 0

Files not scanned:

* C:\PAGEFILE.SYS
* C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT
* C:\WINDOWS\SYSTEM32\CONFIG\SAM
* C:\WINDOWS\SYSTEM32\CONFIG\SECURITY
* C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE
* C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM

Options
Scanning engines:

* F-Secure USS: 2.30.0
* F-Secure Blacklight: 1.0.68
* F-Secure Hydra: 2.8.8110, 2008-10-26
* F-Secure Pegasus: 1.20.0, 2008-09-22
* F-Secure AVP: 7.0.171, 2008-10-25

Scanning options:

* Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML ZIP XXX ANI AVB BAT CMD JPG LSP MAP MHT MIF PHP POT SWF WMF NWS TAR
* Use Advanced heuristics
Make sure you do this.
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    • [external image: Posted Image]

    You could start a topic in our Windows Forum and post the "periodic call of rundll32.exe" issue.
    Let them know we checked for spyware/malware/virus'.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI