und Teil II :
Code:
Alles auswählen Aufklappen ATTFilter
R0 CLFS;Common Log (CLFS);C:\Windows\system32\CLFS.sys [2008-01-18 247352]
R0 Ecache;ReadyBoost Caching Driver;C:\Windows\system32\drivers\ecache.sys [2008-01-18 143416]
R0 FileInfo;File Information FS MiniFilter;C:\Windows\system32\drivers\fileinfo.sys [2008-01-18 58936]
R0 msahci;msahci;C:\Windows\system32\drivers\msahci.sys [2006-11-02 23144]
R0 msisadrv;ISA/EISA-Klassentreiber;C:\Windows\system32\drivers\msisadrv.sys [2008-01-18 16440]
R0 spldr;Security Processor Loader Driver;C:\Windows\system32\drivers\spldr.sys [2008-01-18 21048]
R0 volmgr;Treiber für Volume-Manager;C:\Windows\system32\drivers\volmgr.sys [2008-01-18 52792]
R0 volmgrx;Dynamic Volume Manager;C:\Windows\system32\drivers\volmgrx.sys [2008-01-18 294456]
R1 DfsC;DFS Namespace Client Driver;C:\Windows\system32\Drivers\dfsc.sys [2008-01-18 75264]
R1 nsiproxy;NSI proxy service;C:\Windows\system32\drivers\nsiproxy.sys [2008-01-18 16384]
R1 RDPENCDD;RDP Encoder Mirror Driver;C:\Windows\system32\drivers\rdpencdd.sys [2008-01-18 6144]
R1 Smb;Nachrichtenorientiertes TCP/IP- und TCP/IPv6-Protokoll (SMB-Sitzung);C:\Windows\system32\DRIVERS\smb.sys [2008-01-18 66560]
R1 tdx;NetIO-Legacy-TDI-Supporttreiber;C:\Windows\system32\DRIVERS\tdx.sys [2008-01-18 71680]
R1 Wanarpv6;Remote Access IPv6 ARP Driver;C:\Windows\system32\DRIVERS\wanarp.sys [2008-01-18 62464]
R2 AudioEndpointBuilder;Windows-Audio-Endpunkterstellung;C:\Windows\System32\svchost.exe [2008-01-18 21504]
R2 BFE;Basisfiltermodul;C:\Windows\system32\svchost.exe [2008-01-18 21504]
R2 DPS;Diagnoserichtliniendienst;C:\Windows\System32\svchost.exe [2008-01-18 21504]
R2 EMDMgmt;ReadyBoost;C:\Windows\system32\svchost.exe [2008-01-18 21504]
R2 FDResPub;Funktionssuche-Ressourcenveröffentlichung;C:\Windows\system32\svchost.exe [2008-01-18 21504]
R2 gpsvc;Gruppenrichtlinienclient;C:\Windows\system32\svchost.exe [2008-01-18 21504]
R2 IKEEXT;IKE- und AuthIP IPsec-Schlüsselerstellungsmodule;C:\Windows\system32\svchost.exe [2008-01-18 21504]
R2 iphlpsvc;IP-Hilfsdienst;C:\Windows\System32\svchost.exe [2008-01-18 21504]
R2 KtmRm;KtmRm für Distributed Transaction Coordinator;C:\Windows\System32\svchost.exe [2008-01-18 21504]
R2 lltdio;E/A-Treiber für Verbindungsschicht-Topologieerkennungszuordnung;C:\Windows\system32\DRIVERS\lltdio.sys [2008-01-18 47104]
R2 luafv;UAC File Virtualization;C:\Windows\system32\drivers\luafv.sys [2008-01-18 84480]
R2 MMCSS;Multimediaklassenplaner;C:\Windows\system32\svchost.exe [2008-01-18 21504]
R2 MpsSvc;Windows-Firewall;C:\Windows\system32\svchost.exe [2008-01-18 21504]
R2 netprofm;Netzwerklistendienst;C:\Windows\System32\svchost.exe [2008-01-18 21504]
R2 NlaSvc;NLA (Network Location Awareness);C:\Windows\System32\svchost.exe [2008-01-18 21504]
R2 nsi;Netzwerkspeicher-Schnittstellendienst;C:\Windows\system32\svchost.exe [2008-01-18 21504]
R2 PcaSvc;Programmkompatibilitäts-Assistent-Dienst;C:\Windows\system32\svchost.exe [2008-01-18 21504]
R2 PEAUTH;PEAUTH;C:\Windows\system32\drivers\peauth.sys [2006-11-02 878080]
R2 ProfSvc;Benutzerprofildienst;C:\Windows\system32\svchost.exe [2008-01-18 21504]
R2 slsvc;Softwarelizenzierung;C:\Windows\system32\SLsvc.exe [2008-01-18 2623488]
R2 SysMain;Superfetch;C:\Windows\system32\svchost.exe [2008-01-18 21504]
R2 TabletInputService;Tablet PC-Eingabedienst;C:\Windows\System32\svchost.exe [2008-01-18 21504]
R2 tcpipreg;TCP/IP Registry Compatibility;C:\Windows\system32\drivers\tcpipreg.sys [2008-01-18 30208]
R2 UxSms;Sitzungs-Manager für Desktopfenster-Manager;C:\Windows\System32\svchost.exe [2008-01-18 21504]
R2 WerSvc;Windows-Fehlerberichterstattungsdienst;C:\Windows\System32\svchost.exe [2008-01-18 21504]
R2 Wlansvc;Automatische WLAN-Konfiguration;C:\Windows\system32\svchost.exe [2008-01-18 21504]
R2 WPDBusEnum;Enumeratordienst für tragbare Geräte;C:\Windows\system32\svchost.exe [2008-01-18 21504]
R3 Appinfo;Anwendungsinformationen;C:\Windows\system32\svchost.exe [2008-01-18 21504]
R3 bowser;Bowser;C:\Windows\system32\DRIVERS\bowser.sys [2008-01-18 69632]
R3 DXGKrnl;LDDM Graphics Subsystem;C:\Windows\system32\drivers\dxgkrnl.sys [2008-08-02 625152]
R3 iScsiPrt;iScsiPort-Treiber;C:\Windows\system32\DRIVERS\msiscsi.sys [2008-01-18 181304]
R3 KeyIso;CNG-Schlüsselisolation;C:\Windows\system32\lsass.exe [2008-01-18 9728]
R3 monitor;Microsoft Monitor-Klassenfunktionstreiber-Dienst;C:\Windows\system32\DRIVERS\monitor.sys [2008-01-18 41984]
R3 mpsdrv;Windows-Firewallautorisierungstreiber;C:\Windows\system32\drivers\mpsdrv.sys [2008-01-18 64000]
R3 mrxsmb10;SMB 1.x MiniRedirector;C:\Windows\system32\DRIVERS\mrxsmb10.sys [2008-05-08 211968]
R3 mrxsmb20;SMB 2.0 MiniRedirector;C:\Windows\system32\DRIVERS\mrxsmb20.sys [2008-01-18 78848]
R3 NativeWifiP;NativeWiFi-Filter;C:\Windows\system32\DRIVERS\nwifi.sys [2008-05-20 148480]
R3 srv2;srv2;C:\Windows\system32\DRIVERS\srv2.sys [2008-01-18 144384]
R3 srvnet;srvnet;C:\Windows\system32\DRIVERS\srvnet.sys [2008-01-18 98304]
R3 tunnel;Microsoft-IPv6-Tunnelminiport-Adaptertreiber;C:\Windows\system32\DRIVERS\tunnel.sys [2008-01-18 23040]
R3 umbus;UMBus-Enumerator-Treiber;C:\Windows\system32\DRIVERS\umbus.sys [2008-01-18 34816]
R3 WdiSystemHost;Diagnosesystemhost;C:\Windows\System32\svchost.exe [2008-01-18 21504]
S2 Automatisches LiveUpdate - Scheduler;Automatisches LiveUpdate - Scheduler;C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe [ ]
S2 LVPrcSrv;Process Monitor;C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [2007-07-20 137752]
S2 TBS;TPM-Basisdienste;C:\Windows\System32\svchost.exe [2008-01-18 21504]
S3 BrFiltLo;Brother USB Mass-Storage Lower Filter Driver;C:\Windows\system32\drivers\brfiltlo.sys [2006-11-02 13568]
S3 BrFiltUp;Brother USB Mass-Storage Upper Filter Driver;C:\Windows\system32\drivers\brfiltup.sys [2006-11-02 5248]
S3 BrUsbSer;Brother MFC USB Serial WDM Driver;C:\Windows\system32\drivers\brusbser.sys [2006-11-02 11904]
S3 CertPropSvc;Zertifikatverteilung;C:\Windows\system32\svchost.exe [2008-01-18 21504]
S3 DFSR;DFS-Replikation;C:\Windows\system32\DFSR.exe [2008-01-18 2091520]
S3 E1G60;Intel(R) PRO/1000 NDIS 6 Adapter Driver;C:\Windows\system32\DRIVERS\E1G60I32.sys [2006-11-02 117760]
S3 fdPHost;Funktionssuchanbieter-Host;C:\Windows\system32\svchost.exe [2008-01-18 21504]
S3 Filetrace;FileTrace;C:\Windows\system32\drivers\filetrace.sys [2008-01-18 27648]
S3 IPBusEnum;PnP-X-IP-Busauflistung;C:\Windows\system32\svchost.exe [2008-01-18 21504]
S3 lltdsvc;Verbindungsschicht-Topologieerkennungs-Zuordnungsprogramm;C:\Windows\System32\svchost.exe [2008-01-18 21504]
S3 MSiSCSI;Microsoft iSCSI-Initiator-Dienst;C:\Windows\system32\svchost.exe [2008-01-18 21504]
S3 MsRPC;MsRPC;C:\Windows\system32\drivers\MsRPC.sys [2008-01-18 163384]
S3 p2pimsvc;Peernetzwerkidentitäts-Manager;C:\Windows\System32\svchost.exe [2008-01-18 21504]
S3 p2psvc;Peernetzwerk-Gruppenzuordnung;C:\Windows\System32\svchost.exe [2008-01-18 21504]
S3 PDNMp50;PDNMp50 NDIS Protocol Driver;C:\Windows\system32\drivers\PDNMp50.sys [2006-11-28 28224]
S3 PDNSp50;PDNSp50 NDIS Protocol Driver;C:\Windows\system32\drivers\PDNSp50.sys [2006-11-28 27072]
S3 pla;Leistungsprotokolle und -warnungen;C:\Windows\System32\svchost.exe [2008-01-18 21504]
S3 PNRPAutoReg;PNRP-Computernamenveröffentlichungs-Dienst;C:\Windows\System32\svchost.exe [2008-01-18 21504]
S3 PNRPsvc;Peer Name Resolution-Protokoll;C:\Windows\System32\svchost.exe [2008-01-18 21504]
S3 QWAVE;Verbessertes Windows-Audio/Video-Streaming;C:\Windows\system32\svchost.exe [2008-01-18 21504]
S3 SCPolicySvc;Richtlinie zum Entfernen der Scmartcard;C:\Windows\system32\svchost.exe [2008-01-18 21504]
S3 SDRSVC;Windows-Sicherung;C:\Windows\system32\svchost.exe [2008-01-18 21504]
S3 SessionEnv;Terminaldienstekonfiguration;C:\Windows\System32\svchost.exe [2008-01-18 21504]
S3 sffp_mmc;SFF Storage Protocol Driver for MMC;C:\Windows\system32\drivers\sffp_mmc.sys [2006-11-02 12800]
S3 SLUINotify;SL-Benutzerschnittstellen-Benachrichtigungsdienst;C:\Windows\system32\svchost.exe [2008-01-18 21504]
S3 THREADORDER;Server für Threadsortierung;C:\Windows\system32\svchost.exe [2008-01-18 21504]
S3 TrustedInstaller;Windows Modules Installer;C:\Windows\servicing\TrustedInstaller.exe [2008-01-18 39424]
S3 tssecsrv;Terminal Services Security Filter Driver;C:\Windows\system32\DRIVERS\tssecsrv.sys [2008-01-18 23552]
S3 UI0Detect;Erkennung interaktiver Dienste;C:\Windows\system32\UI0Detect.exe [2008-01-18 35840]
S3 uliagpkx;Uli AGP Bus Filter;C:\Windows\system32\drivers\uliagpkx.sys [2006-11-02 58472]
S3 wcncsvc;Windows-Sofortverbindung - Konfigurationsregistrierungsstelle;C:\Windows\System32\svchost.exe [2008-01-18 21504]
S3 WcsPlugInService;Windows-Farbsystem;C:\Windows\system32\svchost.exe [2008-01-18 21504]
S3 WdiServiceHost;Diagnosediensthost;C:\Windows\System32\svchost.exe [2008-01-18 21504]
S3 Wecsvc;Windows-Ereignissammlung;C:\Windows\system32\svchost.exe [2008-01-18 21504]
S3 wercplsupport;Unterstützung in der Systemsteuerung unter Lösungen für Probleme;C:\Windows\System32\svchost.exe [2008-01-18 21504]
S3 WinRM;Windows-Remoteverwaltung (WS-Verwaltung);C:\Windows\System32\svchost.exe [2008-01-18 21504]
S3 WPCSvc;Jugendschutz;C:\Windows\system32\svchost.exe [2008-01-18 21504]
S4 adp94xx;adp94xx;C:\Windows\system32\drivers\adp94xx.sys [2006-11-02 420968]
S4 adpahci;adpahci;C:\Windows\system32\drivers\adpahci.sys [2006-11-02 297576]
S4 arcsas;arcsas;C:\Windows\system32\drivers\arcsas.sys [2006-11-02 67688]
S4 Brserid;Brother MFC Serial Port Interface Driver (WDM);C:\Windows\system32\drivers\brserid.sys [2006-11-02 71808]
S4 BrSerWdm;Brother WDM Serial driver;C:\Windows\system32\drivers\brserwdm.sys [2006-11-02 62336]
S4 BrUsbMdm;Brother MFC USB Fax Only Modem;C:\Windows\system32\drivers\brusbmdm.sys [2006-11-02 12160]
S4 circlass;Consumer IR Devices;C:\Windows\system32\drivers\circlass.sys [2006-11-02 35328]
S4 Crusoe;Transmeta Crusoe Processor Driver;C:\Windows\system32\drivers\crusoe.sys [2006-11-02 38912]
S4 elxstor;elxstor;C:\Windows\system32\drivers\elxstor.sys [2006-11-02 316520]
S4 HpCISSs;HpCISSs;C:\Windows\system32\drivers\hpcisss.sys [2006-11-02 37480]
S4 iaStorV;Intel RAID Controller Vista;C:\Windows\system32\drivers\iastorv.sys [2006-11-02 232040]
S4 IPMIDRV;IPMIDRV;C:\Windows\system32\drivers\ipmidrv.sys [2006-11-02 65536]
S4 iteraid;ITERAID_Service_Install;C:\Windows\system32\drivers\iteraid.sys [2006-11-02 35944]
S4 LSI_FC;LSI_FC;C:\Windows\system32\drivers\lsi_fc.sys [2006-11-02 65640]
S4 LSI_SAS;LSI_SAS;C:\Windows\system32\drivers\lsi_sas.sys [2006-11-02 65640]
S4 LSI_SCSI;LSI_SCSI;C:\Windows\system32\drivers\lsi_scsi.sys [2006-11-02 65640]
S4 megasas;megasas;C:\Windows\system32\drivers\megasas.sys [2006-11-02 28776]
S4 mpio;Microsoft Multi-Path Bus Driver;C:\Windows\system32\drivers\mpio.sys [2006-11-02 78952]
S4 msdsm;Microsoft Multi-Path Device Specific Module;C:\Windows\system32\drivers\msdsm.sys [2006-11-02 80488]
S4 nfrd960;nfrd960;C:\Windows\system32\drivers\nfrd960.sys [2006-11-02 45160]
S4 ntrigdigi;N-trig HID Tablet Driver;C:\Windows\system32\drivers\ntrigdigi.sys [2006-11-02 20608]
S4 nvstor;nvstor;C:\Windows\system32\drivers\nvstor.sys [2006-11-02 40040]
S4 ql2300;QLogic Fibre Channel Miniport Driver;C:\Windows\system32\drivers\ql2300.sys [2006-11-02 900712]
S4 ql40xx;QLogic iSCSI Miniport Driver;C:\Windows\system32\drivers\ql40xx.sys [2006-11-02 106088]
S4 SiSRaid4;SiSRaid4;C:\Windows\system32\drivers\sisraid4.sys [2006-11-02 71784]
S4 uliahci;uliahci;C:\Windows\system32\drivers\uliahci.sys [2006-11-02 235112]
S4 ulsata2;ulsata2;C:\Windows\system32\drivers\ulsata2.sys [2006-11-02 115816]
S4 usbcir;eHome Infrared Receiver (USBCIR);C:\Windows\system32\drivers\usbcir.sys [2006-11-02 68608]
S4 ViaC7;VIA C7 Processor Driver;C:\Windows\system32\drivers\viac7.sys [2006-11-02 39424]
S4 vsmraid;vsmraid;C:\Windows\system32\drivers\vsmraid.sys [2006-11-02 112232]
S4 WacomPen;Wacom Serial Pen HID Driver;C:\Windows\system32\drivers\wacompen.sys [2006-11-02 20608]
S4 Wd;Microsoft Watchdog Timer Driver;C:\Windows\system32\drivers\wd.sys [2006-11-02 19560]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
NetworkServiceNetworkRestricted REG_MULTI_SZ PolicyAgent
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
WerSvcGroup REG_MULTI_SZ wersvc
swprv REG_MULTI_SZ swprv
regsvc REG_MULTI_SZ RemoteRegistry
wcssvc REG_MULTI_SZ WcsPlugInService
DcomLaunch REG_MULTI_SZ PlugPlay DcomLaunch
wdisvc REG_MULTI_SZ WdiServiceHost
sdrsvc REG_MULTI_SZ sdrsvc
secsvcs REG_MULTI_SZ WinDefend
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
AeLookupSvc
wercplsupport
Themes
CertPropSvc
SCPolicySvc
lanmanserver
gpsvc
IKEEXT
AudioSrv
FastUserSwitchingCompatibility
Nla
NWCWorkstation
SRService
Wmi
WmdmPmSp
TermService
wuauserv
BITS
ShellHWDetection
LogonHours
PCAudit
helpsvc
uploadmgr
iphlpsvc
seclogon
AppInfo
msiscsi
MMCSS
ProfSvc
EapHost
winmgmt
schedule
SessionEnv
browser
hkmsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4995fdaf-e770-11dc-8a99-806e6f6e6963}]
\shell\AutoRun\command - E:\AutoRun.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
C:\Windows\system32\unregmp2.exe /ShowWMP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI
.
Inhalt des "geplante Tasks" Ordners
.
.
------- Zusätzlicher Suchlauf -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.asus.com
R0 -: HKCU-Main,Default_Search_URL = hxxp://www.google.com/ie
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
O8 -: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 -: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 -: Öffnen mit WordPerfect - C:\Program Files\WordPerfect Office X3\Programs\WPLauncher.hta
O17 -: HKLM\CCS\Interface\{4D377678-9F4A-44FE-824E-3E6E03F9BD75}: NameServer = 217.237.149.205,217.237.151.51
O17 -: HKLM\CCS\Interface\{7ED9B69D-2B5D-4A7C-8CA8-899086669EF3}: NameServer = 192.168.2.1
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-22 11:47:28
Windows 6.0.6001 Service Pack 1 NTFS
Scanne versteckte Prozesse...
Scanne versteckte Autostarteinträge...
Scanne versteckte Dateien...
C:\ADSM_PData_0150
Scan erfolgreich abgeschlossen
versteckte Dateien: 1
**************************************************************************
.
Zeit der Fertigstellung: 2008-09-22 11:49:37
ComboFix-quarantined-files.txt 2008-09-22 09:49:33
Vor Suchlauf: 8.936.714.240 Bytes frei
Nach Suchlauf: 8,105,762,816 Bytes frei
382 --- E O F --- 2008-09-21 09:07:43