Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

keyloggerhk.dll Trojan.peflog.30


  • Please log in to reply

#1
mnadeem

mnadeem

    Member

  • Member
  • PipPip
  • 98 posts
Hi some time ago,, system working good , but know having some problem :tazz:
here is the log file.
Logfile of HijackThis v1.99.1
Scan saved at 15:37:44, on 10/16/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\svchost.exe
H:\Programme\Ahead\InCD\InCDsrv.exe
H:\WINDOWS\system32\spoolsv.exe
H:\WINDOWS\Explorer.EXE
H:\Programme\Winamp\winampa.exe
H:\PROGRA~1\A4Tech\Mouse\Amoumain.exe
H:\Programme\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
H:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe
H:\Programme\Ahead\SIPPS\SIPPS.exe
H:\Programme\RemotelyAnywhere\RAGui.exe
H:\Programme\QuickTime\qttask.exe
H:\Programme\Picasa2\PicasaMediaDetector.exe
H:\Programme\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
H:\WINDOWS\system32\Keylogger.exe
H:\Programme\Ahead\InCD\InCD.exe
H:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
H:\Programme\ICQLite\ICQLite.exe
H:\Programme\Microsoft AntiSpyware\gcasServ.exe
H:\Programme\DirectUpdate v4\DUControl.exe
H:\Programme\SlySoft\AnyDVD\AnyDVD.exe
H:\Programme\CyberLink\PowerVCRII\Agent.exe
H:\Programme\Softwin\BitDefender9\bdoesrv.exe
H:\programme\softwin\bitdefender9\bdnagent.exe
H:\programme\softwin\bitdefender9\bdswitch.exe
H:\Programme\Yahoo!\Messenger\ypager.exe
H:\WINDOWS\system32\cisvc.exe
H:\Programme\DirectUpdate v4\DUEngine.exe
H:\New vnc\Twd Remote Anything v5.1.30 Server Directory 4.1.30\TWD.Remote.Anything.v5.1.30 + Server Directory 4.1.30\ds.exe
H:\Programme\Spybot - Search & Destroy\TeaTimer.exe
H:\Programme\Skype\Phone\Skype.exe
H:\Programme\ewido\security suite\ewidoctrl.exe
H:\WINDOWS\SYSTEM32\GEARSEC.EXE
H:\Programme\Microsoft AntiSpyware\gcasDtServ.exe
H:\WINDOWS\System32\snmp.exe
H:\WINDOWS\system32\svchost.exe
H:\Programme\Gemeinsame Dateien\Ulead Systems\DVD\ULCDRSvr.exe
H:\Programme\UltraVNC\winvnc.exe
H:\Programme\Gemeinsame Dateien\Softwin\BitDefender Communicator\xcommsvr.exe
H:\WINDOWS\system32\fxssvc.exe
H:\WINDOWS\system32\mqsvc.exe
H:\Programme\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe
H:\Programme\NetInspectFX\NetInspectFX.exe
H:\Programme\MSN Messenger\msnmsgr.exe
H:\Programme\Messenger\msmsgs.exe
H:\Programme\T-Online\T-Online_Software_6\Info-Cockpit\INFOCOCKPIT.EXE
H:\WINDOWS\system32\mqtgsvc.exe
H:\Programme\Google\Google Talk\googletalk.exe
H:\Programme\ineen\ineen.exe
H:\WINDOWS\system32\ctfmon.exe
C:\Program Files\emule\emule.exe
H:\Programme\InterVideo\Common\Bin\WinCinemaMgr.exe
H:\Programme\Teledat\IWatch.exe
H:\WINDOWS\system32\cidaemon.exe
H:\Programme\Phoner\phoner.exe
H:\Programme\Runtime Software\RemoteByMail\REM.exe
H:\Programme\Microsoft Office\Office\1031\msoffice.exe
H:\PROGRA~1\T-Online\T-ONLI~1\BASIS-~1\Basis2\kernel.exe
H:\Programme\CardPrograms\SCMaster 2.027\SCMSwitch.exe
H:\PROGRA~1\T-Online\T-ONLI~1\BASIS-~1\Basis2\sc_watch.exe
H:\WINDOWS\system32\inetsrv\inetinfo.exe
H:\WINDOWS\system32\cidaemon.exe
H:\PROGRA~1\T-Online\T-ONLI~1\Notifier\Notifier.exe
H:\WINDOWS\Explorer.EXE
H:\Programme\Avant Browser\avant.exe
H:\Programme\Copernic Agent\CopernicAgent.exe
H:\Programme\Outlook Express\msimn.exe
H:\Programme\Gemeinsame Dateien\Softwin\BitDefender Update Service\livesrv.exe
H:\Programme\Gemeinsame Dateien\Softwin\BitDefender Scan Server\bdss.exe
H:\Programme\Softwin\BitDefender9\vsserv.exe
h:\progra~1\softwin\bitdef~3\bdmcon.exe
H:\systemclean\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c...rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.c...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.c...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.c...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.c...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1:80
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - H:\Programme\ICQToolbar\toolbaru.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - H:\Programme\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - H:\Programme\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {206E52E0-D52E-11D4-AD54-0000E86C26F6} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - H:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - H:\Programme\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - H:\Programme\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - H:\Programme\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - h:\programme\google\googletoolbar2.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - H:\Programme\MSN Apps\MSN Toolbar\01.02.4000.1001\de\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - H:\Programme\MSN Apps\MSN Toolbar\01.02.4000.1001\de\msntb.dll
O3 - Toolbar: Copernic Agent - {F2E259E8-0FC8-438C-A6E0-342DD80FA53E} - H:\PROGRA~1\COPERN~1\COPERN~1.DLL
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - H:\Programme\ICQToolbar\toolbaru.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - H:\Programme\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - h:\programme\google\googletoolbar2.dll
O4 - HKLM\..\Run: [WinVNC] "H:\Programme\UltraVNC\winvnc.exe" -servicehelper
O4 - HKLM\..\Run: [WinampAgent] H:\Programme\Winamp\winampa.exe
O4 - HKLM\..\Run: [WheelMouse] H:\PROGRA~1\A4Tech\Mouse\Amoumain.exe
O4 - HKLM\..\Run: [VirtualCloneDrive] "H:\Programme\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [ToADiMon.exe] H:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis1\ToADiMon.exe -TOnlineAutodialStart
O4 - HKLM\..\Run: [TkBellExe] "H:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SIPPS] H:\Programme\Ahead\SIPPS\SIPPS.exe
O4 - HKLM\..\Run: [Remote_Agent] H:\Programme\CyberLink\PowerVCRII\RemoteAgent.exe
O4 - HKLM\..\Run: [RemotelyAnywhere GUI] "H:\Programme\RemotelyAnywhere\RAGui.exe"
O4 - HKLM\..\Run: [QuickTime Task] "H:\Programme\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Picasa Media Detector] H:\Programme\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [NeroFilterCheck] H:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LWBMOUSE] H:\Programme\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
O4 - HKLM\..\Run: [Keylogger] H:\WINDOWS\system32\Keylogger.exe
O4 - HKLM\..\Run: [InCD] H:\Programme\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [iKeyWorks] H:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
O4 - HKLM\..\Run: [ICQ Lite] H:\Programme\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] H:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [gcasServ] "H:\Programme\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [DUControl] "H:\Programme\DirectUpdate v4\DUControl.exe"
O4 - HKLM\..\Run: [CloneCDTray] "H:\Programme\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [BitPump] "H:\Programme\AnalogX\BitPump\bitpump.exe" /VerifySettings
O4 - HKLM\..\Run: [AnyDVD] H:\Programme\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [Agent] H:\Programme\CyberLink\PowerVCRII\Agent.exe
O4 - HKLM\..\Run: [BDMCon] h:\progra~1\softwin\bitdef~3\bdmcon.exe
O4 - HKLM\..\Run: [BDOESRV] "H:\Programme\Softwin\BitDefender9\bdoesrv.exe"
O4 - HKLM\..\Run: [BDNewsAgent] "h:\progra~1\softwin\bitdef~3\bdnagent.exe"
O4 - HKLM\..\Run: [BDSwitchAgent] "h:\progra~1\softwin\bitdef~3\bdswitch.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] H:\Programme\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [SpybotSD TeaTimer] H:\Programme\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Skype] "H:\Programme\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray
O4 - HKCU\..\Run: [PowerBar] "H:\Programme\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe" /AtBootTime
O4 - HKCU\..\Run: [NetInspectFX] H:\Programme\NetInspectFX\NetInspectFX.exe
O4 - HKCU\..\Run: [MsnMsgr] "H:\Programme\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "H:\Programme\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [InfoCockpit] H:\Programme\T-Online\T-Online_Software_6\Info-Cockpit\INFOCOCKPIT.EXE /nosplash
O4 - HKCU\..\Run: [googletalk] "H:\Programme\Google\Google Talk\googletalk.exe" /autostart
O4 - HKCU\..\Run: [eyeBeam SIP Client] "H:\Programme\ineen\ineen.exe"
O4 - HKCU\..\Run: [DynSite] "H:\Programme\NoelD\DynSite for Windows\DynSite.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] H:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ccleaner] "H:\Programme\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\emule\emule.exe -AutoStart
O4 - HKCU\..\RunOnce: [ICQ Lite] H:\Programme\ICQLite\ICQLite.exe -trayboot
O4 - Global Startup: Adobe Gamma Loader.lnk = H:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = H:\Programme\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Configuration Utility.lnk = H:\Programme\Proxim\RangeLAN-DS Utility\Config.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = H:\Programme\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: ISDNWatch.lnk = H:\Programme\Teledat\IWatch.exe
O4 - Global Startup: Microsoft Office.lnk = H:\Programme\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Phoner.lnk = H:\Programme\Phoner\phoner.exe
O4 - Global Startup: RemoteByMail.lnk = H:\Programme\Runtime Software\RemoteByMail\REM.exe
O4 - Global Startup: SC-Master Tray Switch.lnk = H:\Programme\CardPrograms\SCMaster 2.027\SCMSwitch.exe
O8 - Extra context menu item: &Google-Suche - res://h:\programme\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &ICQ Toolbar Search - res://H:\Programme\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: &Ins Deutsche übersetzen - res://h:\programme\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: &Yahoo! Search - file:///H:\Programme\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Alle Bilder von gleichem Server filtern - H:\Programme\Avant Browser\AddAllToADBlackList.htm
O8 - Extra context menu item: Im Cache gespeicherte Seite - res://h:\programme\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: In neuem Avant Browser öffnen - H:\Programme\Avant Browser\OpenInNewBrowser.htm
O8 - Extra context menu item: Open with BitPump - H:\Programme\AnalogX\BitPump\ieint.htm
O8 - Extra context menu item: Suchen - H:\Programme\Avant Browser\Search.htm
O8 - Extra context menu item: Suchen mit Copernic Agent - H:\Programme\Copernic Agent\Web\SearchExt.htm
O8 - Extra context menu item: Verweisseiten - res://h:\programme\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///H:\Programme\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///H:\Programme\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///H:\Programme\Yahoo!\Common/ycsms.htm
O8 - Extra context menu item: Zur Werbebanner-Filterliste hinzufügen - H:\Programme\Avant Browser\AddToADBlackList.htm
O8 - Extra context menu item: Ähnliche Seiten - res://h:\programme\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Öffne alle Links auf dieser Seite... - H:\Programme\Avant Browser\OpenAllLinks.htm
O9 - Extra button: (no name) - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - H:\PROGRA~1\COPERN~1\COPERN~1.EXE
O9 - Extra 'Tools' menuitem: Starten von Copernic Agent - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - H:\PROGRA~1\COPERN~1\COPERN~1.EXE
O9 - Extra button: BINGOOO - {2193E982-BB99-419F-8DF2-2B029E0C8E6E} - C:\Program Files\BINGOOO\BINGOOO.exe
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - H:\Programme\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Copernic Agent - {688DC797-DC11-46A7-9F1B-445F4F58CE6E} - H:\PROGRA~1\COPERN~1\COPERN~1.EXE
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - H:\Programme\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - H:\Programme\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Programme\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'spacklsp.dll' missing
O12 - Plugin for .spop: H:\Programme\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://downloadcente...trolLite_EN.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1119969307479
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1126004716128
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pdownloader.cab
O16 - DPF: {E2B7DB22-38C5-11D5-91F6-00104BDB8FF9} (LEAD Video RGB Converter) - http://www.eprintdri...bs/LMVRGBxf.cab
O16 - DPF: {E2B7DB7E-38C5-11D5-91F6-00104BDB8FF9} - http://www.eprintdri...bs/LCodcScr.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.h.../qdiagh.cab?326
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://qazi-dc1235f...ivex/RACtrl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{16A9DE4B-D66D-4594-81BD-E3C96C2DDDCB}: NameServer = 192.168.121.252,192.168.121.253
O17 - HKLM\System\CS1\Services\Tcpip\..\{16A9DE4B-D66D-4594-81BD-E3C96C2DDDCB}: NameServer = 192.168.121.252,192.168.121.253
O17 - HKLM\System\CS2\Services\Tcpip\..\{16A9DE4B-D66D-4594-81BD-E3C96C2DDDCB}: NameServer = 192.168.121.252,192.168.121.253
O17 - HKLM\System\CS3\Services\Tcpip\..\{16A9DE4B-D66D-4594-81BD-E3C96C2DDDCB}: NameServer = 192.168.121.252,192.168.121.253
O20 - Winlogon Notify: RAinit - H:\WINDOWS\SYSTEM32\RAinit.dll
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - H:\Programme\Gemeinsame Dateien\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: AVM FRITZ!web Routing Service (de_serv) - AVM Berlin - H:\PROGRAMME\TELEDAT\de_serv.exe
O23 - Service: DirectUpdate engine (DirectUpdate) - http://www.directupdate.net/ - H:\Programme\DirectUpdate v4\DUEngine.exe
O23 - Service: RA Directory Server (DS) - TWD Industries SAS - H:\New vnc\Twd Remote Anything v5.1.30 Server Directory 4.1.30\TWD.Remote.Anything.v5.1.30 + Server Directory 4.1.30\ds.exe
O23 - Service: ewido security suite control - ewido networks - H:\Programme\ewido\security suite\ewidoctrl.exe
O23 - Service: GEARSecurity - GEAR Software - H:\WINDOWS\SYSTEM32\GEARSEC.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - H:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - H:\Programme\Ahead\InCD\InCDsrv.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - H:\Programme\Gemeinsame Dateien\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: RA Server (Slave) - Unknown owner - H:\WINDOWS\Slave.exe
O23 - Service: T-Online DSL-Manager (TODslService) - T-Systems International GmbH - H:\Programme\T-Online\DSL-Manager\TODslSvc.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - H:\Programme\TuneUp Utilities 2006\WinStylerThemeSvc.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - H:\Programme\Gemeinsame Dateien\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - H:\Programme\Softwin\BitDefender9\vsserv.exe" /service (file missing)
O23 - Service: VNC Server (winvnc) - Unknown owner - H:\Programme\UltraVNC\winvnc.exe" -service (file missing)
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - H:\Programme\Gemeinsame Dateien\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)
  • 0

Advertisements


#2
mnadeem

mnadeem

    Member

  • Topic Starter
  • Member
  • PipPip
  • 98 posts
Hi ,, there are also many diffrent type of virus ,, bitdeffendre is still looking ,, here is the new log file. :tazz: this keyloggerhk.dll every time comes when i started new programm ,, can i delete from windows/system . please tell me , if im do so windows will function or not ,,
Logfile of HijackThis v1.99.1
Scan saved at 21:35:28, on 10/16/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\svchost.exe
H:\Programme\Ahead\InCD\InCDsrv.exe
H:\WINDOWS\system32\spoolsv.exe
H:\WINDOWS\system32\cisvc.exe
H:\Programme\DirectUpdate v4\DUEngine.exe
H:\New vnc\Twd Remote Anything v5.1.30 Server Directory 4.1.30\TWD.Remote.Anything.v5.1.30 + Server Directory 4.1.30\ds.exe
H:\Programme\ewido\security suite\ewidoctrl.exe
H:\WINDOWS\SYSTEM32\GEARSEC.EXE
H:\WINDOWS\system32\inetsrv\inetinfo.exe
H:\WINDOWS\System32\snmp.exe
H:\WINDOWS\system32\svchost.exe
H:\Programme\Gemeinsame Dateien\Ulead Systems\DVD\ULCDRSvr.exe
H:\Programme\UltraVNC\winvnc.exe
H:\Programme\Gemeinsame Dateien\Softwin\BitDefender Communicator\xcommsvr.exe
H:\WINDOWS\system32\mqsvc.exe
H:\WINDOWS\Explorer.EXE
H:\WINDOWS\system32\mqtgsvc.exe
H:\Programme\Winamp\winampa.exe
H:\PROGRA~1\A4Tech\Mouse\Amoumain.exe
H:\Programme\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
H:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe
H:\Programme\Ahead\SIPPS\SIPPS.exe
H:\Programme\RemotelyAnywhere\RAGui.exe
H:\Programme\QuickTime\qttask.exe
H:\Programme\Picasa2\PicasaMediaDetector.exe
H:\Programme\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
H:\WINDOWS\system32\Keylogger.exe
H:\Programme\Ahead\InCD\InCD.exe
H:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
H:\Programme\ICQLite\ICQLite.exe
H:\Programme\Microsoft AntiSpyware\gcasServ.exe
H:\Programme\DirectUpdate v4\DUControl.exe
H:\Programme\SlySoft\AnyDVD\AnyDVD.exe
H:\Programme\CyberLink\PowerVCRII\Agent.exe
H:\Programme\Softwin\BitDefender9\bdoesrv.exe
H:\progra~1\softwin\bitdef~3\bdnagent.exe
H:\progra~1\softwin\bitdef~3\bdswitch.exe
H:\Programme\Yahoo!\Messenger\ypager.exe
H:\Programme\Spybot - Search & Destroy\TeaTimer.exe
H:\Programme\Skype\Phone\Skype.exe
H:\Programme\NetInspectFX\NetInspectFX.exe
H:\Programme\MSN Messenger\msnmsgr.exe
H:\Programme\Messenger\msmsgs.exe
H:\Programme\T-Online\T-Online_Software_6\Info-Cockpit\INFOCOCKPIT.EXE
H:\Programme\Google\Google Talk\googletalk.exe
H:\Programme\ineen\ineen.exe
H:\WINDOWS\system32\cidaemon.exe
H:\WINDOWS\system32\ctfmon.exe
H:\WINDOWS\system32\dllhost.exe
C:\Program Files\emule\emule.exe
H:\WINDOWS\system32\inetsrv\DavCData.exe
H:\WINDOWS\system32\cidaemon.exe
H:\Programme\Microsoft AntiSpyware\gcasDtServ.exe
H:\Programme\InterVideo\Common\Bin\WinCinemaMgr.exe
H:\Programme\Teledat\IWatch.exe
H:\Programme\Phoner\phoner.exe
H:\Programme\Runtime Software\RemoteByMail\REM.exe
H:\Programme\CardPrograms\SCMaster 2.027\SCMSwitch.exe
H:\Programme\Microsoft Office\Office\1031\msoffice.exe
H:\PROGRA~1\T-Online\T-ONLI~1\BASIS-~1\Basis2\kernel.exe
H:\PROGRA~1\T-Online\T-ONLI~1\BASIS-~1\Basis2\sc_watch.exe
H:\PROGRA~1\T-Online\T-ONLI~1\Notifier\Notifier.exe
H:\Programme\Gemeinsame Dateien\Softwin\BitDefender Update Service\livesrv.exe
H:\Programme\Gemeinsame Dateien\Softwin\BitDefender Scan Server\bdss.exe
H:\Programme\Softwin\BitDefender9\vsserv.exe
h:\progra~1\softwin\bitdef~3\bdmcon.exe
H:\Programme\Outlook Express\msimn.exe
H:\Programme\Avant Browser\avant.exe
H:\WINDOWS\Explorer.EXE
H:\systemclean\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c...rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.c...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.c...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.c...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.c...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1:80
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - H:\Programme\ICQToolbar\toolbaru.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - H:\Programme\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - H:\Programme\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {206E52E0-D52E-11D4-AD54-0000E86C26F6} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - H:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - H:\Programme\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - H:\Programme\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - H:\Programme\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - h:\programme\google\googletoolbar2.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - H:\Programme\MSN Apps\MSN Toolbar\01.02.4000.1001\de\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - H:\Programme\MSN Apps\MSN Toolbar\01.02.4000.1001\de\msntb.dll
O3 - Toolbar: Copernic Agent - {F2E259E8-0FC8-438C-A6E0-342DD80FA53E} - H:\PROGRA~1\COPERN~1\COPERN~1.DLL
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - H:\Programme\ICQToolbar\toolbaru.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - H:\Programme\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - h:\programme\google\googletoolbar2.dll
O4 - HKLM\..\Run: [WinVNC] "H:\Programme\UltraVNC\winvnc.exe" -servicehelper
O4 - HKLM\..\Run: [WinampAgent] H:\Programme\Winamp\winampa.exe
O4 - HKLM\..\Run: [WheelMouse] H:\PROGRA~1\A4Tech\Mouse\Amoumain.exe
O4 - HKLM\..\Run: [VirtualCloneDrive] "H:\Programme\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [ToADiMon.exe] H:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis1\ToADiMon.exe -TOnlineAutodialStart
O4 - HKLM\..\Run: [TkBellExe] "H:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SIPPS] H:\Programme\Ahead\SIPPS\SIPPS.exe
O4 - HKLM\..\Run: [Remote_Agent] H:\Programme\CyberLink\PowerVCRII\RemoteAgent.exe
O4 - HKLM\..\Run: [RemotelyAnywhere GUI] "H:\Programme\RemotelyAnywhere\RAGui.exe"
O4 - HKLM\..\Run: [QuickTime Task] "H:\Programme\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Picasa Media Detector] H:\Programme\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [NeroFilterCheck] H:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LWBMOUSE] H:\Programme\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
O4 - HKLM\..\Run: [Keylogger] H:\WINDOWS\system32\Keylogger.exe
O4 - HKLM\..\Run: [InCD] H:\Programme\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [iKeyWorks] H:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
O4 - HKLM\..\Run: [ICQ Lite] H:\Programme\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] H:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [gcasServ] "H:\Programme\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [DUControl] "H:\Programme\DirectUpdate v4\DUControl.exe"
O4 - HKLM\..\Run: [CloneCDTray] "H:\Programme\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [BitPump] "H:\Programme\AnalogX\BitPump\bitpump.exe" /VerifySettings
O4 - HKLM\..\Run: [AnyDVD] H:\Programme\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [Agent] H:\Programme\CyberLink\PowerVCRII\Agent.exe
O4 - HKLM\..\Run: [BDMCon] h:\progra~1\softwin\bitdef~3\bdmcon.exe
O4 - HKLM\..\Run: [BDOESRV] "H:\Programme\Softwin\BitDefender9\bdoesrv.exe"
O4 - HKLM\..\Run: [BDNewsAgent] "h:\progra~1\softwin\bitdef~3\bdnagent.exe"
O4 - HKLM\..\Run: [BDSwitchAgent] "h:\progra~1\softwin\bitdef~3\bdswitch.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] H:\Programme\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [SpybotSD TeaTimer] H:\Programme\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Skype] "H:\Programme\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray
O4 - HKCU\..\Run: [NetInspectFX] H:\Programme\NetInspectFX\NetInspectFX.exe
O4 - HKCU\..\Run: [MsnMsgr] "H:\Programme\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "H:\Programme\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [InfoCockpit] H:\Programme\T-Online\T-Online_Software_6\Info-Cockpit\INFOCOCKPIT.EXE /nosplash
O4 - HKCU\..\Run: [googletalk] "H:\Programme\Google\Google Talk\googletalk.exe" /autostart
O4 - HKCU\..\Run: [eyeBeam SIP Client] "H:\Programme\ineen\ineen.exe"
O4 - HKCU\..\Run: [DynSite] "H:\Programme\NoelD\DynSite for Windows\DynSite.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] H:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ccleaner] "H:\Programme\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\emule\emule.exe -AutoStart
O4 - HKCU\..\RunOnce: [ICQ Lite] H:\Programme\ICQLite\ICQLite.exe -trayboot
O4 - Global Startup: Adobe Gamma Loader.lnk = H:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = H:\Programme\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Configuration Utility.lnk = H:\Programme\Proxim\RangeLAN-DS Utility\Config.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = H:\Programme\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: ISDNWatch.lnk = H:\Programme\Teledat\IWatch.exe
O4 - Global Startup: Microsoft Office.lnk = H:\Programme\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Phoner.lnk = H:\Programme\Phoner\phoner.exe
O4 - Global Startup: RemoteByMail.lnk = H:\Programme\Runtime Software\RemoteByMail\REM.exe
O4 - Global Startup: SC-Master Tray Switch.lnk = H:\Programme\CardPrograms\SCMaster 2.027\SCMSwitch.exe
O8 - Extra context menu item: &Google-Suche - res://h:\programme\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &ICQ Toolbar Search - res://H:\Programme\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: &Ins Deutsche übersetzen - res://h:\programme\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: &Yahoo! Search - file:///H:\Programme\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Alle Bilder von gleichem Server filtern - H:\Programme\Avant Browser\AddAllToADBlackList.htm
O8 - Extra context menu item: Im Cache gespeicherte Seite - res://h:\programme\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: In neuem Avant Browser öffnen - H:\Programme\Avant Browser\OpenInNewBrowser.htm
O8 - Extra context menu item: Open with BitPump - H:\Programme\AnalogX\BitPump\ieint.htm
O8 - Extra context menu item: Suchen - H:\Programme\Avant Browser\Search.htm
O8 - Extra context menu item: Suchen mit Copernic Agent - H:\Programme\Copernic Agent\Web\SearchExt.htm
O8 - Extra context menu item: Verweisseiten - res://h:\programme\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///H:\Programme\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///H:\Programme\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///H:\Programme\Yahoo!\Common/ycsms.htm
O8 - Extra context menu item: Zur Werbebanner-Filterliste hinzufügen - H:\Programme\Avant Browser\AddToADBlackList.htm
O8 - Extra context menu item: Ähnliche Seiten - res://h:\programme\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Öffne alle Links auf dieser Seite... - H:\Programme\Avant Browser\OpenAllLinks.htm
O9 - Extra button: (no name) - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - H:\PROGRA~1\COPERN~1\COPERN~1.EXE
O9 - Extra 'Tools' menuitem: Starten von Copernic Agent - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - H:\PROGRA~1\COPERN~1\COPERN~1.EXE
O9 - Extra button: BINGOOO - {2193E982-BB99-419F-8DF2-2B029E0C8E6E} - C:\Program Files\BINGOOO\BINGOOO.exe
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - H:\Programme\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Copernic Agent - {688DC797-DC11-46A7-9F1B-445F4F58CE6E} - H:\PROGRA~1\COPERN~1\COPERN~1.EXE
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - H:\Programme\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - H:\Programme\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Programme\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'spacklsp.dll' missing
O12 - Plugin for .spop: H:\Programme\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://downloadcente...trolLite_EN.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1119969307479
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1126004716128
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pdownloader.cab
O16 - DPF: {E2B7DB22-38C5-11D5-91F6-00104BDB8FF9} (LEAD Video RGB Converter) - http://www.eprintdri...bs/LMVRGBxf.cab
O16 - DPF: {E2B7DB7E-38C5-11D5-91F6-00104BDB8FF9} - http://www.eprintdri...bs/LCodcScr.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.h.../qdiagh.cab?326
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://qazi-dc1235f...ivex/RACtrl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{16A9DE4B-D66D-4594-81BD-E3C96C2DDDCB}: NameServer = 192.168.121.252,192.168.121.253
O17 - HKLM\System\CS1\Services\Tcpip\..\{16A9DE4B-D66D-4594-81BD-E3C96C2DDDCB}: NameServer = 192.168.121.252,192.168.121.253
O17 - HKLM\System\CS2\Services\Tcpip\..\{16A9DE4B-D66D-4594-81BD-E3C96C2DDDCB}: NameServer = 192.168.121.252,192.168.121.253
O17 - HKLM\System\CS3\Services\Tcpip\..\{16A9DE4B-D66D-4594-81BD-E3C96C2DDDCB}: NameServer = 192.168.121.252,192.168.121.253
O20 - Winlogon Notify: RAinit - H:\WINDOWS\SYSTEM32\RAinit.dll
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - H:\Programme\Gemeinsame Dateien\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: AVM FRITZ!web Routing Service (de_serv) - AVM Berlin - H:\PROGRAMME\TELEDAT\de_serv.exe
O23 - Service: DirectUpdate engine (DirectUpdate) - http://www.directupdate.net/ - H:\Programme\DirectUpdate v4\DUEngine.exe
O23 - Service: RA Directory Server (DS) - TWD Industries SAS - H:\New vnc\Twd Remote Anything v5.1.30 Server Directory 4.1.30\TWD.Remote.Anything.v5.1.30 + Server Directory 4.1.30\ds.exe
O23 - Service: ewido security suite control - ewido networks - H:\Programme\ewido\security suite\ewidoctrl.exe
O23 - Service: GEARSecurity - GEAR Software - H:\WINDOWS\SYSTEM32\GEARSEC.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - H:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - H:\Programme\Ahead\InCD\InCDsrv.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - H:\Programme\Gemeinsame Dateien\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: RA Server (Slave) - Unknown owner - H:\WINDOWS\Slave.exe
O23 - Service: T-Online DSL-Manager (TODslService) - T-Systems International GmbH - H:\Programme\T-Online\DSL-Manager\TODslSvc.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - H:\Programme\TuneUp Utilities 2006\WinStylerThemeSvc.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - H:\Programme\Gemeinsame Dateien\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - H:\Programme\Softwin\BitDefender9\vsserv.exe" /service (file missing)
O23 - Service: VNC Server (winvnc) - Unknown owner - H:\Programme\UltraVNC\winvnc.exe" -service (file missing)
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - H:\Programme\Gemeinsame Dateien\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)
  • 0

#3
mnadeem

mnadeem

    Member

  • Topic Starter
  • Member
  • PipPip
  • 98 posts
hi please help ,, i do not know what to do ,, there are many missing file ,, i have try to delete them ,, but wont go.. why :tazz:
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP