| TR/Crypt.XPACK.Gen TR/Trash.Gen TR/Agent.57344 ComboFix Log Zitat:
ComboFix 08-05-15.3 - xx 2008-05-18 13:14:22.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1031.18.1570 [GMT 2:00]
ausgeführt von:: C:\Dokumente und Einstellungen\xx\Desktop\ComboFix.exe WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((( Dateien erstellt von 2008-04-18 bis 2008-05-18 ))))))))))))))))))))))))))))))
.
2008-05-17 14:11 . 2008-05-17 14:11 <DIR> d-------- C:\Programme\Trend Micro
2008-05-17 13:17 . 2008-05-17 13:17 <DIR> d-------- C:\WINDOWS\ERUNT
2008-05-16 20:55 . 2008-05-16 20:55 <DIR> d-a------ C:\WINDOWS\zts2.exe
2008-05-16 20:55 . 2008-05-16 20:55 <DIR> d-a------ C:\WINDOWS\system32\vcmgcd32.dll
2008-05-16 20:55 . 2008-05-16 20:55 <DIR> d-a------ C:\WINDOWS\system32\iifgfgf.dll
2008-05-16 20:55 . 2008-05-16 20:55 <DIR> d-a------ C:\WINDOWS\rundll16.exe
2008-05-16 20:55 . 2008-05-16 20:55 <DIR> d-a------ C:\WINDOWS\rundl132.dll
2008-05-16 20:55 . 2008-05-16 20:55 <DIR> d-a------ C:\WINDOWS\logo1_.exe
2008-05-16 19:16 . 2008-05-16 20:53 50 --a------ C:\WINDOWS\Lic.xxx
2008-05-16 19:15 . 2008-04-14 07:53 153,600 --a------ C:\WINDOWS\R.COM
2008-05-16 19:15 . 2008-04-14 07:53 140,800 --a------ C:\WINDOWS\system32\T.COM
2008-05-15 15:27 . 2008-04-15 08:09 3,523,624 --a------ C:\procexp.exe
2008-05-15 14:44 . 2008-05-16 22:09 <DIR> d-------- C:\Programme\Malwarebytes' Anti-Malware
2008-05-15 14:44 . 2008-05-15 14:44 <DIR> d-------- C:\Dokumente und Einstellungen\xx\Anwendungsdaten\Malwarebytes
2008-05-15 14:44 . 2008-05-15 14:44 <DIR> d-------- C:\Dokumente und Einstellungen\All Users.WINDOWS\Anwendungsdaten\Malwarebytes
2008-05-15 14:44 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-15 14:44 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-05-15 14:30 . <DIR> C:\Dokumente und Einstellungen\NetworkService.NT-AUTORIT-T
2008-05-15 14:30 . <DIR> C:\Dokumente und Einstellungen\LocalService.NT-AUTORIT-T
2008-05-15 13:57 . 2008-05-17 14:16 1,024 --ah----- C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG
2008-05-15 13:50 . 2008-05-15 13:50 <DIR> d-------- C:\Programme\CleanUp!
2008-05-15 13:47 . 2008-05-18 12:02 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-05-15 13:47 . 2008-05-15 13:47 1,409 --a------ C:\WINDOWS\QTFont.for
2008-05-15 11:50 . 2008-05-15 14:30 109,807 --a------ C:\WINDOWS\BM93f00213.xml
2008-05-14 11:02 . 2008-05-14 11:02 <DIR> d-------- C:\Programme\XP_Key_Changer
2008-05-14 11:02 . 2008-02-21 01:12 36,864 --a------ C:\WINDOWS\system32\MD5.ocx
2008-05-14 11:01 . 2008-04-14 07:52 29,184 --a--c--- C:\WINDOWS\system32\dllcache\msoobe.exe
2008-05-14 10:49 . 2008-05-14 10:49 1,024 --ah----- C:\Dokumente und Einstellungen\Default User\NTUSER.DAT.LOG
2008-05-14 10:34 . 2008-04-13 22:04 1,897,408 --------- C:\WINDOWS\system32\drivers\nv4_mini.sys
2008-05-12 23:14 . 2008-05-12 23:30 720,896 --a------ C:\WINDOWS\iun6002ev.exe
2008-05-12 23:09 . 2008-05-12 23:09 <DIR> d-------- C:\Programme\NVidia Corporation
2008-05-08 10:41 . 2008-05-08 10:41 140,061 --a------ C:\romanghostwidowgo1.jpg
2008-05-08 10:39 . 2008-05-08 10:39 191,032 --a------ C:\screenshot_2008-05-06-18-06-21.jpg
2008-04-30 23:14 . 2008-04-30 23:14 <DIR> d-------- C:\Dokumente und Einstellungen\xx\Anwendungsdaten\InstallShield
2008-04-30 23:09 . 2008-04-30 23:09 <DIR> d-------- C:\WINDOWS\uninstall\FAKEFACTORY CM
2008-04-30 23:08 . 2008-04-30 23:47 11,346 --a------ C:\WINDOWS\uninstall\FAKEFACTORY CM Setup Log.txt
2008-04-25 14:34 . 2008-04-25 14:34 <DIR> d-------- C:\Programme\WMA-MP3.com
2008-04-25 13:39 . 2008-04-25 13:39 <DIR> d-------- C:\Programme\iTunes
2008-04-25 13:39 . 2008-04-25 13:39 <DIR> d-------- C:\Programme\iPod
2008-04-24 20:50 . 2004-10-16 13:38 299,008 --a------ C:\Dokumente und Einstellungen\xx\Anwendungsdaten\DESINSTALADOR_AVCINEEDSP.exe
2008-04-24 20:07 . 2008-04-24 21:08 <DIR> d-------- C:\Programme\Glest_3.1.2
2008-04-24 20:06 . 2008-04-24 20:26 <DIR> d-------- C:\Programme\Video Strip Poker Supreme
2008-04-24 20:05 . 2008-04-24 20:34 <DIR> d-------- C:\Programme\Ratmania
2008-04-24 19:55 . 2008-04-24 19:55 <DIR> d-------- C:\Programme\Alcachofa Soft
2008-04-24 18:47 . 2008-04-24 18:47 <DIR> d-------- C:\Programme\IrfanView
2008-04-22 18:06 . 2007-12-11 01:14 481,689 --a------ C:\1197352557615.jpg
8 Datei(en) . 14,688,139 C:\ComboFix\Bytes
3 Datei(en) . 299,566 C:\ComboFix\Bytes
2 Datei(en) . 1,180,672 C:\ComboFix\Bytes
2 Datei(en) . 263,168 C:\ComboFix\Bytes
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-18 11:04 --------- d-----w C:\Programme\Mozilla Thunderbird
2008-05-17 12:28 --------- d-----w C:\Programme\TuneUp Utilities 2007
2008-05-17 09:49 --------- d-----w C:\Dokumente und Einstellungen\xx\Anwendungsdaten\ICQ
2008-05-16 10:58 --------- d-----w C:\Dokumente und Einstellungen\xx\Anwendungsdaten\OpenOffice.org2
2008-05-15 12:36 --------- d-----w C:\Programme\ICQToolbar
2008-05-14 23:14 --------- d-----w C:\Programme\CoHTest
2008-05-14 09:06 --------- d-----w C:\Dokumente und Einstellungen\xx\Anwendungsdaten\uTorrent
2008-05-14 09:05 513,024 ----a-w C:\WINDOWS\system32\winlogon.exe
2008-05-12 21:11 --------- d--h--w C:\Programme\InstallShield Installation Information
2008-05-07 11:58 --------- d-----w C:\Programme\Steam
2008-05-06 23:20 --------- d---a-w C:\Dokumente und Einstellungen\All Users.WINDOWS\Anwendungsdaten\TEMP
2008-05-06 12:59 --------- d-----w C:\Dokumente und Einstellungen\xx\Anwendungsdaten\dvdcss
2008-05-01 20:34 --------- d-----w C:\Programme\FlashGet
2008-04-30 21:33 --------- d-----w C:\Programme\DLH98
2008-04-30 21:25 --------- d-----w C:\Programme\The Witcher Demo
2008-04-30 21:21 --------- d-----w C:\Programme\Gothic III
2008-04-30 21:13 --------- d-----w C:\Dokumente und Einstellungen\xx\Anwendungsdaten\concept design
2008-04-30 20:17 --------- d-----w C:\Programme\NCSoft
2008-04-30 19:33 --------- d-----w C:\Dokumente und Einstellungen\xx\Anwendungsdaten\GetRightToGo
2008-04-26 09:42 --------- d-----w C:\Programme\Apple Software Update
2008-04-25 11:37 --------- d-----w C:\Programme\QuickTime
2008-04-24 20:52 --------- d-----w C:\Programme\Frets on Fire
2008-04-18 07:31 --------- d-----w C:\Programme\7-Zip
2008-04-17 11:33 --------- d-----w C:\Programme\ICQ6
2008-04-16 13:43 --------- d-----w C:\Programme\Acclaim
2008-04-15 21:20 --------- d-----w C:\Programme\CohSplasher
2008-04-14 16:51 --------- d-----w C:\Programme\Tale of Tales
2008-04-14 06:06 1,804 ----a-w C:\WINDOWS\system32\dcache.bin
2008-04-14 05:55 333,312 ----a-w C:\WINDOWS\system32\netsetup.exe
2008-04-14 05:52 99,840 ----a-w C:\WINDOWS\system32\loadperf.dll
2008-04-14 05:51 762,368 ----a-w C:\WINDOWS\system32\winntbbu.dll
2008-04-14 05:51 76,288 ----a-w C:\WINDOWS\system32\uniime.dll
2008-04-14 05:51 731,648 ----a-w C:\WINDOWS\system32\ntdll.dll
2008-04-14 05:51 57,375 ----a-w C:\WINDOWS\system32\odbcji32.dll
2008-04-14 05:51 5,632 ----a-w C:\WINDOWS\system32\wmi.dll
2008-04-14 05:51 4,126 ----a-w C:\WINDOWS\system32\msdxmlc.dll
2008-04-14 05:51 24,064 ----a-w C:\WINDOWS\system32\pidgen.dll
2008-04-14 05:32 80,384 ----a-w C:\WINDOWS\system32\drivers\parport.sys
2008-04-14 05:32 73,472 ----a-w C:\WINDOWS\system32\drivers\sr.sys
2008-04-14 05:32 68,224 ----a-w C:\WINDOWS\system32\drivers\pci.sys
2008-04-14 05:32 46,848 ----a-w C:\WINDOWS\system32\drivers\p3.sys
2008-04-14 05:32 120,576 ----a-w C:\WINDOWS\system32\drivers\pcmcia.sys
2008-04-14 05:30 2,026,496 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-04-14 05:29 4,096 ----a-w C:\WINDOWS\system32\dsprpres.dll
2008-04-14 05:29 2,147,840 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-04-14 05:28 800,384 ----a-w C:\WINDOWS\system32\drivers\dmboot.sys
2008-04-14 05:28 37,632 ----a-w C:\WINDOWS\system32\drivers\isapnp.sys
2008-04-14 05:28 25,216 ----a-w C:\WINDOWS\system32\drivers\kbdclass.sys
2008-04-14 05:28 154,112 ----a-w C:\WINDOWS\system32\drivers\dmio.sys
2008-04-14 05:28 14,720 ----a-w C:\WINDOWS\system32\drivers\kbdhid.sys
2008-04-14 05:27 93,184 ----a-w C:\WINDOWS\system32\msxml6r.dll
2008-04-14 05:27 40,448 ----a-w C:\WINDOWS\system32\drivers\intelppm.sys
2008-04-14 05:26 81,408 ------w C:\WINDOWS\system32\msshavmsg.dll
2008-04-14 05:26 51,712 ----a-w C:\WINDOWS\system32\inetres.dll
2008-04-14 05:26 40,832 ----a-w C:\WINDOWS\system32\drivers\crusoe.sys
2008-04-14 05:25 65,536 ----a-w C:\WINDOWS\system32\drivers\serial.sys
2008-04-14 05:25 572,928 ----a-w C:\WINDOWS\system32\shdoclc.dll
2008-04-14 05:25 52,992 ----a-w C:\WINDOWS\system32\drivers\i8042prt.sys
2008-04-14 05:24 25,856 ------w C:\WINDOWS\system32\drivers\hidbth.sys
2008-04-14 05:24 10,752 ----a-w C:\WINDOWS\system32\gpkrsrc.dll
2008-04-14 05:23 1,845,760 ----a-w C:\WINDOWS\system32\win32k.sys
2008-04-14 05:22 68,096 ----a-w C:\WINDOWS\system32\browselc.dll
2008-04-14 05:22 57,728 ----a-w C:\WINDOWS\system32\drivers\redbook.sys
2008-04-14 05:22 53,760 ----a-w C:\WINDOWS\system32\drivers\volsnap.sys
2008-04-14 05:22 44,672 ----a-w C:\WINDOWS\system32\drivers\fips.sys
2008-04-14 05:22 273,920 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-04-14 05:21 39,936 ----a-w C:\WINDOWS\system32\drivers\processr.sys
2008-04-14 05:21 327,168 ------w C:\WINDOWS\system32\drivers\ati2mtaa.sys
2008-04-14 05:20 41,856 ----a-w C:\WINDOWS\system32\drivers\amdk7.sys
2008-04-14 05:20 41,472 ----a-w C:\WINDOWS\system32\drivers\amdk6.sys
2008-04-14 05:19 30,336 ----a-w C:\WINDOWS\system32\drivers\modem.sys
2008-04-14 05:19 23,552 ----a-w C:\WINDOWS\system32\drivers\mouclass.sys
2008-04-14 05:19 188,800 ----a-w C:\WINDOWS\system32\drivers\acpi.sys
2008-04-13 22:58 175,744 ----a-w C:\WINDOWS\system32\drivers\rdbss.sys
2008-04-13 22:51 162,816 ----a-w C:\WINDOWS\system32\drivers\netbt.sys
2008-04-13 22:50 91,520 ----a-w C:\WINDOWS\system32\drivers\ndiswan.sys
2008-04-13 22:50 361,344 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-04-13 22:50 182,656 ----a-w C:\WINDOWS\system32\drivers\ndis.sys
2008-04-13 22:49 75,264 ----a-w C:\WINDOWS\system32\drivers\ipsec.sys
2008-04-13 22:49 51,328 ----a-w C:\WINDOWS\system32\drivers\rasl2tp.sys
2008-04-13 22:49 48,384 ----a-w C:\WINDOWS\system32\drivers\raspptp.sys
2008-04-13 22:49 146,048 ----a-w C:\WINDOWS\system32\drivers\portcls.sys
2008-04-13 22:49 138,112 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-04-13 22:47 83,072 ----a-w C:\WINDOWS\system32\drivers\wdmaud.sys
2008-04-13 22:47 456,576 ----a-w C:\WINDOWS\system32\drivers\mrxsmb.sys
2008-04-13 22:47 105,344 ----a-w C:\WINDOWS\system32\drivers\mup.sys
2008-04-13 22:46 49,536 ----a-w C:\WINDOWS\system32\drivers\classpnp.sys
2008-04-13 22:46 141,056 ----a-w C:\WINDOWS\system32\drivers\ks.sys
2008-04-13 22:45 60,800 ----a-w C:\WINDOWS\system32\drivers\sysaudio.sys
2008-04-13 22:45 574,976 ----a-w C:\WINDOWS\system32\drivers\ntfs.sys
2008-04-13 22:45 334,848 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-04-13 22:44 63,744 ----a-w C:\WINDOWS\system32\drivers\cdfs.sys
2008-04-13 22:44 143,744 ----a-w C:\WINDOWS\system32\drivers\fastfat.sys
2008-04-13 22:30 225,664 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-04-13 22:30 19,072 ----a-w C:\WINDOWS\system32\drivers\tdi.sys
2008-04-13 22:27 41,472 ----a-w C:\WINDOWS\system32\drivers\raspppoe.sys
2008-04-13 22:27 40,576 ----a-w C:\WINDOWS\system32\drivers\ndproxy.sys
2008-04-13 22:27 34,560 ----a-w C:\WINDOWS\system32\drivers\wanarp.sys
2008-04-13 22:27 20,864 ----a-w C:\WINDOWS\system32\drivers\ipinip.sys
2008-04-13 22:27 152,832 ----a-w C:\WINDOWS\system32\drivers\ipnat.sys
.
------- Sigcheck -------
2007-06-04 23:26 507392 db37d307003055ed09711cb3417814c7 C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
2008-04-14 07:53 513024 f09a527b422e25c478e38caa0e44417a C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
2008-05-14 11:05 513024 63f596358d91e0de887e3d031cccf5c6 C:\WINDOWS\system32\winlogon.exe
.
((((((((((((((((((((((((((((( snapshot@2008-05-15_14.27.17.64 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-15 12:06:36 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-18 10:02:24 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-17 00:22:37 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-05-17 11:18:10 9,068,544 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\ntuser.dat
+ 2008-05-17 11:18:10 274,432 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2008-05-17 00:22:37 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-05-17 11:17:51 9,068,544 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\ntuser.dat
+ 2008-05-17 11:17:51 274,432 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
- 2008-04-06 05:56:20 19,836,024 ----a-w C:\WINDOWS\system32\MRT.exe
+ 2008-05-09 21:35:04 16,863,864 ----a-w C:\WINDOWS\system32\MRT.exe
.
(((((((((((((((((((((((((((( Autostart Punkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Hinweis* leere Eintrage & legitime Standardeintrage werden nicht angezeigt.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 13:35 90112]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 07:52 15360]
"SpybotSD TeaTimer"="C:\Programme\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"ICQ"="C:\Programme\ICQ6\ICQ.exe" [2008-04-01 12:40 172280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 13:35 90112]
"avgnt"="C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe" [2008-04-16 22:37 262401]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-11 09:50 20992 C:\WINDOWS\LOGI_MWX.EXE]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 00:32 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 00:31 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 00:32 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 00:32 455168]
"Cmaudio"="cmicnfg.cpl" []
"Launch LGDCore"="C:\Programme\Logitech\G-series Software\LGDCore.exe" [2006-03-06 17:31 1122304]
"Launch LCDMon"="C:\Programme\Logitech\G-series Software\LCDMon.exe" [2006-03-06 17:14 497152]
"SunJavaUpdateSched"="C:\Programme\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"LXSUPMON"="C:\WINDOWS\system32\LXSUPMON.exe" [2002-01-28 13:48 885760]
"TkBellExe"="C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" [2007-12-11 00:10 185896]
"SoundMan"="SOUNDMAN.EXE" [2006-11-17 06:42 577536 C:\WINDOWS\soundman.exe]
"AtiPTA"="atiptaxx.exe" [2006-02-22 03:05 344064 C:\WINDOWS\system32\atiptaxx.exe]
"LiveMonitor"="C:\Programme\MSI\Live Update 3\LMonitor.exe" [2008-03-14 11:41 498176]
"amd_dc_opt"="C:\Programme\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2007-07-23 11:06 77824]
"QuickTime Task"="C:\Programme\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Programme\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 07:52 15360]
C:\Dokumente und Einstellungen\All Users.WINDOWS\Startmen\Programme\Autostart\
VistaAccess.lnk - C:\VstaScan\VsAccess.exe [2005-12-21 13:03:16 158208]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
"VIDC.VP31"= vp31vfw.dll
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users.WINDOWS^Startmenü^Programme^Autostart^Adobe Acrobat - Schnellstart.lnk]
path=C:\Dokumente und Einstellungen\All Users.WINDOWS\Startmenü\Programme\Autostart\Adobe Acrobat - Schnellstart.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat - Schnellstart.lnkCommon Startup
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users.WINDOWS^Startmenü^Programme^Autostart^Adobe Reader Synchronizer.lnk]
path=C:\Dokumente und Einstellungen\All Users.WINDOWS\Startmenü\Programme\Autostart\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users.WINDOWS^Startmenü^Programme^Autostart^Registrierungsprogramm ausführen.lnk]
path=C:\Dokumente und Einstellungen\All Users.WINDOWS\Startmenü\Programme\Autostart\Registrierungsprogramm ausführen.lnk
backup=C:\WINDOWS\pss\Registrierungsprogramm ausführen.lnkCommon Startup
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users.WINDOWS^Startmenü^Programme^Autostart^SecureDoc.lnk]
path=C:\Dokumente und Einstellungen\All Users.WINDOWS\Startmenü\Programme\Autostart\SecureDoc.lnk
backup=C:\WINDOWS\pss\SecureDoc.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
--a------ 2006-10-22 23:24 620152 C:\Programme\Adobe CS3\Acrobat 8.0\Acrobat\Acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe_ID0EYTHM]
--a------ 2007-03-20 16:40 1884160 C:\PROGRA~1\GEMEIN~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
--a------ 2007-04-04 00:29 165784 C:\Programme\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
--a------ 2004-08-22 17:05 81920 C:\Programme\D-Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-03-30 10:36 267048 C:\Programme\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-03-28 23:37 413696 C:\Programme\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-01-28 11:43 2097488 C:\Programme\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-07-12 04:00 132496 C:\Programme\Java\jre1.6.0_02\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-12-11 00:10 185896 C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Winamp controller for g15]
C:\Dokumente und Einstellungen\xx\Desktop\Winamp Controller for G15.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"iPod Service"=3 (0x3)
"FLEXnet Licensing Service"=3 (0x3)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"Adobe Version Cue CS3"=3 (0x3)
"Adobe LM Service"=3 (0x3)
"aawservice"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programme\\utorrent\\utorrent.exe"=
"C:\\Programme\\ICQ6\\ICQ.exe"=
"C:\\Programme\\Bonjour\\mDNSResponder.exe"=
"C:\\Programme\\Gemeinsame Dateien\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"C:\\Programme\\WiFiConnector\\NintendoWFCReg.exe"=
"C:\\Programme\\FlashGet\\FlashGet.exe"=
"C:\\Programme\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
"9842:TCP"= 9842:TCP:*isabled:SolidNetworkManager
"9842:UDP"= 9842:UDP:*isabled:SolidNetworkManager
R0 viasraid;viasraid;C:\WINDOWS\system32\DRIVERS\viasraid.sys [2003-10-31 11:22]
R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys [2006-10-17 14:22]
R0 xfilt;VIA SATA IDE Hot-plug Driver;C:\WINDOWS\system32\DRIVERS\xfilt.sys [2006-10-18 11:39]
R1 atitray;atitray;C:\Programme\Radeon Omega Drivers\v4.8.442\ATI Tray Tools\atitray.sys [2007-11-05 09:55]
R2 UxTuneUp;TuneUp Designerweiterung;C:\WINDOWS\System32\svchost.exe [2008-04-14 07:53]
S3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2007-04-17 11:58]
S3 huadio;huadio;c:\huadio.tmp []
S3 VNICPKT5;VNICPKT5 Protocol Driver;C:\WINDOWS\system32\VNICPKT5.SYS []
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
*Newly Created Service* - CATCHME
.
Inhalt des "geplante Tasks" Ordners
"2008-05-16 15:16:45 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Programme\TuneUp Utilities 2007\SystemOptimizer.exe
"2008-05-16 14:10:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Programme\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, xx://www.gmer.net
Rootkit scan 2008-05-18 13:17:09
Windows 5.1.2600 Service Pack 3 NTFS
Scanne versteckte Prozesse...
Scanne versteckte Autostart Einträge...
Scanne versteckte Dateien...
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\huadio]
"ImagePath"="\??\c:\huadio.tmp"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\ginamsi.dll
.
Zeit der Fertigstellung: 2008-05-18 13:19:47
ComboFix-quarantined-files.txt 2008-05-18 11:19:45
ComboFix2.txt 2008-05-17 12:27:14
ComboFix3.txt 2008-05-15 12:30:09
27 Verzeichnis(se), 61,113,331,712 Bytes frei
29 Verzeichnis(se), 61,097,234,432 Bytes frei
320 --- E O F --- 2008-05-17 12:09:56
|
__________________ |