Dr.Phoenix | 20.06.2007 21:30 | Habe nun einmal VundoFix laufen lassen, der auch prompt was gefunden hat. Da aber immer noch eine Datei als Trojaner identifiziert wird, hier mein Combofix-Log: Code:
ComboFix 07-06-18.2 - C:\Dokumente und Einstellungen\Dominik\Desktop\ComboFix.exe
"Dominik" - 2007-06-20 22:03:28 - Service Pack 2 NTFS
((((((((((((((((((((((((( Files Created from 2007-05-20 to 2007-06-20 )))))))))))))))))))))))))))))))
2007-06-20 21:47 2,097,152 --ah----- C:\DOKUME~1\ADMINI~1\NTUSER.DAT
2007-06-20 21:47 <DIR> dr-h----- C:\DOKUME~1\ADMINI~1\Anwendungsdaten
2007-06-20 21:47 <DIR> dr------- C:\DOKUME~1\ADMINI~1\Startmen
2007-06-20 21:47 <DIR> dr------- C:\DOKUME~1\ADMINI~1\Favoriten
2007-06-20 21:47 <DIR> dr------- C:\DOKUME~1\ADMINI~1\Eigene Dateien
2007-06-20 21:47 <DIR> d--h----- C:\DOKUME~1\ADMINI~1\Vorlagen
2007-06-20 21:47 <DIR> d--h----- C:\DOKUME~1\ADMINI~1\Netzwerkumgebung
2007-06-20 21:47 <DIR> d--h----- C:\DOKUME~1\ADMINI~1\Lokale Einstellungen
2007-06-20 21:47 <DIR> d--h----- C:\DOKUME~1\ADMINI~1\Druckumgebung
2007-06-20 21:47 <DIR> d-------- C:\DOKUME~1\ADMINI~1\WINDOWS
2007-06-20 21:47 <DIR> d-------- C:\DOKUME~1\ADMINI~1\ANWEND~1\InterTrust
2007-06-20 21:47 <DIR> d-------- C:\DOKUME~1\ADMINI~1\ANWEND~1\Help
2007-06-20 21:47 <DIR> d-------- C:\DOKUME~1\ADMINI~1\ANWEND~1\CyberLink
2007-06-20 21:26 <DIR> d-------- C:\VundoFix Backups
2007-06-20 21:05 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-06-20 17:40 <DIR> d-------- C:\WINDOWS\system32\SoftwareDistribution
2007-06-20 15:56 427,864 --a------ C:\WINDOWS\system32\XceedZip.dll
2007-06-20 15:56 31,254 --------- C:\WINDOWS\system32\awtsqpm.dll
2007-06-20 15:55 <DIR> d-------- C:\Programme\DriverGenius
2007-06-16 16:53 <DIR> d-------- C:\CloneDVDTemp
2007-06-16 16:41 <DIR> d-------- C:\DOKUME~1\ALLUSE~1\ANWEND~1\Ahead
2007-06-15 11:33 <DIR> d-------- C:\Programme\FreePDF_XP
2007-06-15 11:33 <DIR> d-------- C:\DOKUME~1\ALLUSE~1\FreePDF
2007-06-12 19:40 <DIR> d-------- C:\DOKUME~1\ALLUSE~1\ANWEND~1\ENotebook 10.0
2007-06-12 19:38 <DIR> d-------- C:\Programme\ProWorks
2007-06-12 19:37 <DIR> d-------- C:\DOKUME~1\ALLUSE~1\ANWEND~1\CambridgeSoft
2007-06-12 19:31 33,340 --------- C:\WINDOWS\system32\dbmsqlgc.dll
2007-06-12 19:31 24,576 --------- C:\WINDOWS\system32\dbmsgnet.dll
2007-06-12 19:30 <DIR> d-------- C:\Programme\Microsoft SQL Server
2007-06-12 14:21 <DIR> d-------- C:\Programme\CambridgeSoft
2007-06-12 13:48 <DIR> d-------- C:\Programme\PeerGuardian2
2007-06-06 09:53 64,880 --a------ C:\WINDOWS\system32\drivers\pe3agqwb.sys
2007-06-06 09:53 407,152 --a------ C:\WINDOWS\system32\pr2agqwb.exe
2007-06-06 09:52 55,160 --a------ C:\WINDOWS\system32\drivers\ps6agqwb.sys
2007-06-05 19:13 <DIR> d-------- C:\Programme\DAEMON Tools
2007-06-05 18:35 49,536 --a------ C:\WINDOWS\system32\drivers\ahtuezr3.sys
2007-06-01 17:39 <DIR> d-------- C:\Programme\Skype
2007-06-01 17:39 <DIR> d-------- C:\Programme\Gemeinsame Dateien\Skype
2007-05-31 23:24 <DIR> d-------- C:\Programme\iPod
2007-05-31 08:45 524,288 --a------ C:\WINDOWS\system32\DivXsm.exe
2007-05-31 08:44 823,296 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2007-05-31 08:44 823,296 --a------ C:\WINDOWS\system32\divx_xx07.dll
2007-05-31 08:44 802,816 --a------ C:\WINDOWS\system32\divx_xx11.dll
2007-05-31 08:44 740,442 --a------ C:\WINDOWS\system32\DivX.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-06-20 18:09:14 -------- d-----w C:\DOKUME~1\Dominik\ANWEND~1\uTorrent
2007-06-20 17:26:24 -------- d-----w C:\Programme\Tunebite
2007-06-20 15:41:03 -------- d--h--w C:\Programme\WindowsUpdate
2007-06-20 14:33:13 -------- d--h--w C:\Programme\InstallShield Installation Information
2007-06-20 13:03:50 7,779 ----a-w C:\WINDOWS\mozver.dat
2007-06-16 14:27:32 -------- d-----w C:\Programme\Elaborate Bytes
2007-06-14 14:32:44 -------- d-----w C:\DOKUME~1\Dominik\ANWEND~1\Skype
2007-06-13 05:27:09 -------- d-----w C:\DOKUME~1\Dominik\ANWEND~1\ICQ
2007-06-12 17:31:44 80,196 ----a-w C:\WINDOWS\system32\perfc007.dat
2007-06-12 17:31:44 426,516 ----a-w C:\WINDOWS\system32\perfh007.dat
2007-06-08 16:32:30 -------- d-----w C:\Programme\DivX
2007-06-06 18:10:48 -------- d-----w C:\Programme\Gemeinsame Dateien\Sony Shared
2007-06-06 18:10:13 -------- d-----w C:\Programme\Video Store
2007-06-06 18:09:31 -------- d-----w C:\Programme\Gemeinsame Dateien\Ulead Systems
2007-06-05 16:59:39 685,816 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2007-06-02 11:05:55 -------- d-----w C:\Programme\PartyGaming.Net
2007-06-01 15:20:58 -------- d-----w C:\DOKUME~1\Dominik\ANWEND~1\MyPhoneExplorer
2007-05-31 21:24:36 -------- d-----w C:\Programme\iTunes
2007-05-26 10:42:34 10 ----a-w C:\WINDOWS\popcinfo.dat
2007-05-19 20:08:25 86,016 ----a-w C:\WINDOWS\system32\ElbyCDIO.dll
2007-05-16 17:55:20 407,152 ----a-w C:\WINDOWS\system32\pr2agqwc.exe
2007-05-16 17:55:02 64,880 ----a-w C:\WINDOWS\system32\drivers\pe3agqwc.sys
2007-05-16 17:54:44 55,160 ----a-w C:\WINDOWS\system32\drivers\ps6agqwc.sys
2007-05-16 15:11:44 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-15 18:07:55 -------- d-----w C:\Programme\Ulead CD & DVD PictureShow 4
2007-05-14 21:37:47 -------- d-----w C:\DOKUME~1\Dominik\ANWEND~1\Ulead Systems
2007-05-14 21:35:55 -------- d-----w C:\Programme\Gemeinsame Dateien\InstallShield
2007-05-14 19:56:38 -------- d-----w C:\Programme\Shareaza
2007-05-14 19:56:33 -------- d-----w C:\DOKUME~1\Dominik\ANWEND~1\Shareaza
2007-05-14 19:30:02 74 ---ha-w C:\WINDOWS\YNNHOJED.DLL
2007-05-14 18:32:17 -------- d-----w C:\Programme\Gemeinsame Dateien\InterVideo
2007-05-14 18:31:12 -------- d-----w C:\Programme\Windows Media Components
2007-05-14 14:22:59 -------- d-----w C:\Programme\MyPhoneExplorer
2007-05-14 14:21:50 -------- d-----w C:\Programme\Gemeinsame Dateien\Wise Installation Wizard
2007-05-14 14:21:46 -------- d-----w C:\Programme\Mobile Master
2007-05-14 13:54:07 -------- d-----w C:\DOKUME~1\Dominik\ANWEND~1\Mobile Master
2007-05-10 09:59:55 -------- d-----w C:\Programme\QuickTime
2007-05-09 18:16:32 -------- d-----w C:\Programme\Trillian
2007-05-08 17:40:53 -------- d-----w C:\Programme\rlw32
2007-05-07 12:45:59 -------- d-----w C:\Programme\ICQ6
2007-05-02 16:01:12 -------- d-----w C:\DOKUME~1\Dominik\ANWEND~1\tunebite
2007-04-26 14:12:15 -------- d-----w C:\Programme\Radiograbber
2007-04-25 14:22:27 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-23 00:15:29 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-04-23 00:15:18 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-04-23 00:15:18 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-04-23 00:02:34 73,728 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-04-23 00:02:34 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2007-04-23 00:02:33 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-04-23 00:02:31 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-04-23 00:02:31 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-04-23 00:02:31 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-04-23 00:02:31 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-04-23 00:02:31 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-04-23 00:01:47 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-04-23 00:01:46 124,472 ----a-w C:\WINDOWS\system32\DivXCodecUpdateChecker.exe
2007-04-18 16:13:24 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-16 20:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-16 20:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-16 20:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-16 20:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-16 20:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-16 20:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-16 20:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-16 20:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-04-15 18:11:56 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
2004-12-13 12:08:48 56 --sh--r C:\WINDOWS\system32\F5904193E3.sys
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{066A2CDC-319E-4460-BA45-C24562CD51AA}=C:\WINDOWS\system32\awtsqpm.dll [2007-06-20 15:56]
{6A7E5524-010E-4773-B916-E7E5B8445336}=C:\WINDOWS\system32\awvvt.dll []
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Programme\Java\jre1.5.0_06\bin\ssv.dll [2005-11-10 14:22]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2005-03-24 21:20 C:\WINDOWS\SOUNDMAN.EXE]
"avgnt"="C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe" [2007-04-23 18:06]
"D-Link AirPlus G"="C:\Programme\D-Link\AirPlus G\AirGCFG.exe" [2005-11-23 16:04]
"TkBellExe"="C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" [2005-02-27 21:08]
"ANIWZCS2Service"="C:\Programme\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2005-10-19 19:19]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LDM"="C:\Programme\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2006-07-13 19:31]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 09:57]
"ICQ"="C:\Programme\ICQ6\ICQ.exe" [2007-04-25 12:29]
"STYLEXP"="C:\Programme\TGTSoft\StyleXP\StyleXP.exe" [2006-05-24 20:31]
"DAEMON Tools"="C:\Programme\DAEMON Tools\daemon.exe" [2007-04-04 00:29]
"PeerGuardian"="C:\Programme\PeerGuardian2\pg2.exe" [2005-09-18 18:40]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"SSS6_Suite"="C:\Programme\Steganos Security Suite 6\sss.exe" /booting
"SSS6_SAFE"="C:\Programme\Steganos Security Suite 6\safe.exe" /booting
"SSS6_SPM"="C:\Programme\Steganos Security Suite 6\spm.exe" /booting
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoLowDiskSpaceChecks"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"="C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL" [2006-10-27 01:48]
"{066A2CDC-319E-4460-BA45-C24562CD51AA}"="C:\WINDOWS\system32\awtsqpm.dll" [2007-06-20 15:56]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtsqpm]
awtsqpm.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=APITRAP
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^OpenMG Jukebox Startup.lnk]
backup=C:\WINDOWS\pss\OpenMG Jukebox Startup.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Agent]
C:\Programme\Medion\PowerCinema\My_TV\Agent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AltnetPointsManager]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLMIcon]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CapFax]
C:\Programme\Classic PhoneTools\CapFax.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDElbyCDFL]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
"C:\Programme\SlySoft\CloneCD\CloneCDTray.exe" /s
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dit]
Dit.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Programme\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
%systemroot%\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Inet Xp..]
teekids.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkUFind.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MJStarter]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\New.net Startup]
rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVIEW]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P2P Networking]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Programme\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegClean Expert Scheduler]
"C:\Programme\Registry Clean Expert\RCScheduler.exe" /startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WhenUSave]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Messenger"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"TkBellExe"="C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot
"mmtask"="C:\Programme\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
Contents of the 'Scheduled Tasks' folder
2007-06-08 15:17:43 C:\WINDOWS\tasks\1-Click Maintenance.job
2007-04-15 09:41:01 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
**************************************************************************
catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-06-20 22:07:51
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-06-20 22:09:51
C:\ComboFix-quarantined-files.txt ... 2007-06-20 22:09
C:\ComboFix2.txt ... 2007-06-20 21:19
--- E O F --- |