patrick007 | 11.10.2008 18:28 | hier ist das logfile von combofix Code:
ComboFix 08-10-10.09 - Meyer 2008-10-11 19:20:42.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1031.18.1390 [GMT 2:00]
ausgeführt von:: C:\Users\***\Documents\Desktop\Desktop\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Users\Meyer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Videos.url
C:\Users\***\FAVORI~1\Videos.url
C:\Users\***\Favorites\Videos.url
C:\Windows\system32\MSINET.oca
.
((((((((((((((((((((((( Dateien erstellt von 2008-09-11 bis 2008-10-11 ))))))))))))))))))))))))))))))
.
2008-10-11 19:16 . 2008-10-11 19:16 <DIR> d-------- C:\Program Files\CCleaner
2008-10-10 14:08 . 2008-10-10 14:08 124,688 --a------ C:\Windows\System32\MSWINSCK.OCX
2008-10-10 14:08 . 2008-10-10 14:08 18,944 --a------ C:\Windows\System32\wk32.dll
2008-10-10 14:08 . 2008-10-10 14:08 3,584 --a------ C:\Windows\System32\ic32.dll
2008-10-05 15:05 . 2008-10-05 15:06 <DIR> d-------- C:\Users\***\AppData\Roaming\vlc
2008-10-04 16:22 . 2008-10-04 16:24 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-04 16:22 . 2008-09-10 00:04 38,528 --a------ C:\Windows\System32\drivers\mbamswissarmy.sys
2008-10-04 16:22 . 2008-09-10 00:03 17,200 --a------ C:\Windows\System32\drivers\mbam.sys
2008-10-01 17:25 . 2008-10-01 17:25 <DIR> d-------- C:\Users\***\AppData\Roaming\Malwarebytes
2008-10-01 17:25 . 2008-10-01 17:25 <DIR> d-------- C:\Users\All Users\Malwarebytes
2008-10-01 17:25 . 2008-10-01 17:25 <DIR> d-------- C:\ProgramData\Malwarebytes
2008-09-30 18:10 . 2008-09-30 18:10 <DIR> d-------- C:\Program Files\Trend Micro
2008-09-28 21:27 . 2008-09-28 21:29 <DIR> d-------- C:\Users\All Users\Lavasoft
2008-09-28 21:27 . 2008-09-28 21:29 <DIR> d-------- C:\ProgramData\Lavasoft
2008-09-28 21:27 . 2008-09-28 21:27 <DIR> d-------- C:\Program Files\Lavasoft
2008-09-28 21:25 . 2008-09-30 20:59 <DIR> d-------- C:\Windows\DED53B0BB67C4244AE6AD6FD3C28D1EF.TMP
2008-09-28 21:25 . 2008-09-28 21:25 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-09-20 10:20 . 2008-09-20 10:20 <DIR> dr------- C:\Windows\System32\config\systemprofile\Videos
2008-09-20 10:20 . 2008-09-20 10:20 <DIR> dr------- C:\Windows\System32\config\systemprofile\Saved Games
2008-09-20 10:20 . 2008-09-20 10:20 <DIR> dr------- C:\Windows\System32\config\systemprofile\Pictures
2008-09-20 10:20 . 2008-09-20 10:20 <DIR> dr------- C:\Windows\System32\config\systemprofile\Music
2008-09-20 10:20 . 2008-09-20 10:20 <DIR> dr------- C:\Windows\System32\config\systemprofile\Links
2008-09-20 10:20 . 2008-09-20 10:20 <DIR> dr------- C:\Windows\System32\config\systemprofile\Downloads
2008-09-20 10:20 . 2008-09-20 10:20 <DIR> dr------- C:\Windows\System32\config\systemprofile\Documents
2008-09-20 10:20 . 2008-09-20 10:20 <DIR> d-------- C:\Users\All Users\Electronic Arts
2008-09-20 10:20 . 2008-09-20 10:20 <DIR> d-------- C:\ProgramData\Electronic Arts
2008-09-20 10:19 . 2008-09-20 10:20 <DIR> dr------- C:\Windows\System32\config\systemprofile\Searches
2008-09-20 10:16 . 2008-03-05 15:56 3,786,760 --a------ C:\Windows\System32\D3DX9_37.dll
2008-09-20 10:16 . 2007-07-19 18:14 3,727,720 --a------ C:\Windows\System32\d3dx9_35.dll
2008-09-20 10:16 . 2007-05-16 16:45 3,497,832 --a------ C:\Windows\System32\d3dx9_34.dll
2008-09-20 10:16 . 2007-03-12 16:42 3,495,784 --a------ C:\Windows\System32\d3dx9_33.dll
2008-09-20 10:16 . 2006-11-29 13:06 3,426,072 --a------ C:\Windows\System32\d3dx9_32.dll
2008-09-20 10:16 . 2006-09-28 16:05 2,414,360 --a------ C:\Windows\System32\d3dx9_31.dll
2008-09-20 10:16 . 2007-04-04 18:53 81,768 --a------ C:\Windows\System32\xinput1_3.dll
2008-09-20 10:11 . 2008-09-20 10:23 <DIR> d-------- C:\FIFA 09 Demo
2008-09-17 17:38 . 2008-09-17 17:38 <DIR> d-------- C:\Users\All Users\Ashampoo
2008-09-17 17:38 . 2008-09-17 17:38 <DIR> d-------- C:\ProgramData\Ashampoo
2008-09-17 17:34 . 2008-09-17 17:34 <DIR> d-------- C:\Users\All Users\ebay
2008-09-17 17:34 . 2008-09-17 17:34 <DIR> d-------- C:\ProgramData\ebay
2008-09-12 18:50 . 2008-09-22 16:14 <DIR> d-------- C:\Program Files\ICQ6
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-11 17:14 --------- d-----w C:\Users\***\AppData\Roaming\Skype
2008-10-11 16:40 --------- d-----w C:\Users\***\AppData\Roaming\skypePM
2008-10-10 21:44 --------- d-----w C:\Users\***\AppData\Roaming\ICQ
2008-10-10 19:55 --------- d-----w C:\ProgramData\Google Updater
2008-10-10 19:46 --------- d-----w C:\ProgramData\AntiVir PersonalEdition Classic
2008-10-05 13:04 --------- d-----w C:\Program Files\VideoLAN
2008-10-01 16:35 --------- d-----w C:\Program Files\GameSpy Arcade
2008-09-20 08:23 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-20 08:16 --------- d-----w C:\Program Files\EA SPORTS
2008-09-11 13:29 --------- d-----w C:\ProgramData\TrackMania
2008-09-06 21:57 --------- d-----w C:\Program Files\Google
2008-09-06 15:40 --------- d-----w C:\Users\***\AppData\Roaming\FileZilla
2008-09-05 13:26 --------- d-----w C:\Program Files\TmNationsForever
2008-09-01 12:51 --------- d-----w C:\Program Files\Sony Ericsson
2008-08-24 06:05 --------- d-----w C:\Users\***\AppData\Roaming\Logitech
2008-08-24 06:03 0 ---ha-w C:\Windows\system32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf
2008-08-24 06:03 0 ---ha-w C:\Windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2008-08-24 06:03 0 ---ha-w C:\Windows\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf
2008-08-24 06:02 --------- d-----w C:\Program Files\Common Files\Logitech
2008-08-24 06:01 --------- d-----w C:\ProgramData\Logitech
2008-08-24 06:01 --------- d-----w C:\ProgramData\LogiShrd
2008-08-24 06:01 --------- d-----w C:\Program Files\Logitech
2008-08-19 08:15 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-08-14 13:08 --------- d-----w C:\Program Files\Windows Mail
2008-08-02 03:26 36,864 ----a-w C:\Windows\System32\cdd.dll
2008-07-31 03:32 460,288 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-07-31 03:32 28,160 ----a-w C:\Windows\System32\Apphlpdm.dll
2008-07-31 03:32 2,154,496 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-07-31 03:32 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-07-31 01:13 4,240,384 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
2008-07-19 05:10 53,448 ----a-w C:\Windows\System32\wuauclt.exe
2008-07-19 05:10 45,768 ----a-w C:\Windows\System32\wups2.dll
2008-07-19 05:10 36,552 ----a-w C:\Windows\System32\wups.dll
2008-07-19 05:09 563,912 ----a-w C:\Windows\System32\wuapi.dll
2008-07-19 05:09 1,811,656 ----a-w C:\Windows\System32\wuaueng.dll
2008-07-19 03:44 83,456 ----a-w C:\Windows\System32\wudriver.dll
2008-07-19 03:44 1,524,736 ----a-w C:\Windows\System32\wucltux.dll
2008-07-18 20:08 163,904 ----a-w C:\Windows\System32\wuwebv.dll
2008-07-18 18:44 31,232 ----a-w C:\Windows\System32\wuapp.exe
2008-07-16 01:32 2,048 ----a-w C:\Windows\System32\tzres.dll
2008-06-25 13:06 174 --sha-w C:\Program Files\desktop.ini
2008-03-15 08:43 32 ----a-w C:\Users\All Users\ezsid.dat
2008-03-15 08:43 32 ----a-w C:\ProgramData\ezsid.dat
2007-06-28 13:29 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2007-06-28 13:29 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2007-06-28 13:29 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-06-29 68856]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 125952]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2008-02-20 360448]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 2321600]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-02-01 21898024]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" [2007-12-22 221568]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136]
"avgnt"="C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-18 266497]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2007-03-05 868352]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-09-12 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-09-12 8497696]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-09-12 81920]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 C:\Windows\KHALMNPR.Exe]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-08-24 692224]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-518828407-832848686-3804761394-1000]
"EnableNotificationsRef"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{7A52EFB8-B784-4E41-B4B6-129A76C8EEBB}"= UDP:C:\Program Files\GameSpy Arcade\Aphex.exe:GameSpy Arcade
"{1732000A-FE8A-470B-A9EE-B5620D9F6D13}"= TCP:C:\Program Files\GameSpy Arcade\Aphex.exe:GameSpy Arcade
"TCP Query User{D37B5A46-404E-463E-9FA4-53DDA605F5B3}C:\\program files\\ubisoft\\xiii\\system\\xiii.exe"= UDP:C:\program files\ubisoft\xiii\system\xiii.exe:XIII
"UDP Query User{4E60BA58-4223-4B9E-B8EA-44FD5AE267AF}C:\\program files\\ubisoft\\xiii\\system\\xiii.exe"= TCP:C:\program files\ubisoft\xiii\system\xiii.exe:XIII
"TCP Query User{4B50D624-88D8-4191-8FC9-423EF4194EDF}C:\\program files\\zattoo\\zattood.exe"= UDP:C:\program files\zattoo\zattood.exe:zattood
"UDP Query User{89CFCB5C-D446-4048-B978-D91FFBC4A8B7}C:\\program files\\zattoo\\zattood.exe"= TCP:C:\program files\zattoo\zattood.exe:zattood
"TCP Query User{1BCD10EB-023A-44AE-A90F-E38392703793}C:\\program files\\zattoo\\zattoo.exe"= UDP:C:\program files\zattoo\zattoo.exe:
"UDP Query User{91A5D9FE-0E1E-462D-8CAE-CFF6A3C02F33}C:\\program files\\zattoo\\zattoo.exe"= TCP:C:\program files\zattoo\zattoo.exe:
"TCP Query User{3FD261E6-06E4-474C-902E-743DE06C35D4}C:\\program files\\konami\\pro evolution soccer 2008\\pes2008.exe"= UDP:C:\program files\konami\pro evolution soccer 2008\pes2008.exe:Pro Evolution Soccer 2008
"UDP Query User{04DF2199-7E61-46DB-86A9-FD4201C134B6}C:\\program files\\konami\\pro evolution soccer 2008\\pes2008.exe"= TCP:C:\program files\konami\pro evolution soccer 2008\pes2008.exe:Pro Evolution Soccer 2008
"TCP Query User{67D25E9E-5BEA-4A44-95E5-C6FE5DBF3D06}C:\\program files\\tmnationsforever\\tmforever.exe"= UDP:C:\program files\tmnationsforever\tmforever.exe:TmForever
"UDP Query User{27F74CCB-DDA5-4A27-86D0-F693BC0DB914}C:\\program files\\tmnationsforever\\tmforever.exe"= TCP:C:\program files\tmnationsforever\tmforever.exe:TmForever
R1 hwinterface;hwinterface;C:\Windows\system32\Drivers\hwinterface.sys [2007-03-27 3026]
R3 netr73;Conceptronic RT73 Wireles Driver for Vista;C:\Windows\system32\DRIVERS\netr73.sys [2007-05-11 329728]
S3 s716bus;Sony Ericsson Device 716 driver (WDM);C:\Windows\system32\DRIVERS\s716bus.sys [2007-04-04 83208]
S3 s716mdfl;Sony Ericsson Device 716 USB WMC Modem Filter;C:\Windows\system32\DRIVERS\s716mdfl.sys [2007-04-04 15112]
S3 s716mdm;Sony Ericsson Device 716 USB WMC Modem Driver;C:\Windows\system32\DRIVERS\s716mdm.sys [2007-04-04 108552]
S3 s716mgmt;Sony Ericsson Device 716 USB WMC Device Management Drivers (WDM);C:\Windows\system32\DRIVERS\s716mgmt.sys [2007-04-04 100360]
S3 s716nd5;Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (NDIS);C:\Windows\system32\DRIVERS\s716nd5.sys [2007-04-04 23176]
S3 s716obex;Sony Ericsson Device 716 USB WMC OBEX Interface;C:\Windows\system32\DRIVERS\s716obex.sys [2007-04-04 98568]
S3 s716unic;Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (WDM);C:\Windows\system32\DRIVERS\s716unic.sys [2007-04-04 98952]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6aac7b3a-2f1f-11dd-a01a-001a923be07a}]
\shell\AutoRun\command - I:\Autorun.exe
*Newly Created Service* - PROCEXP90
.
Inhalt des "geplante Tasks" Ordners
2008-10-11 C:\Windows\Tasks\User_Feed_Synchronization-{4027E0E3-2040-43D2-90C5-099EE65C532F}.job
- C:\Windows\system32\msfeedssync.exe [2008-01-19 09:33]
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
.
------- Zusätzlicher Suchlauf -------
.
FireFox -: Profile - C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\ny8mbemp.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.yodl.de/href.php?hrefname=FF-splug_google&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://speed.travian.de/dorf1.php
FF -: plugin - C:\Program Files\Google\Google Updater\2.3.1334.1308\npCIDetect13.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-11 19:24:24
Windows 6.0.6001 Service Pack 1 NTFS
Scanne versteckte Prozesse...
Scanne versteckte Autostarteinträge...
Scanne versteckte Dateien...
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
**************************************************************************
.
Zeit der Fertigstellung: 2008-10-11 19:26:03
ComboFix-quarantined-files.txt 2008-10-11 17:26:00
Vor Suchlauf: 14 Verzeichnis(se), 272.133.861.376 Bytes frei
Nach Suchlauf: 22 Verzeichnis(se), 272,094,822,400 Bytes frei
192 --- E O F --- 2008-10-11 11:07:53 |