Theesener | 14.02.2012 23:23 | Das Killerlog Code:
22:29:08.0812 3332 TDSS rootkit removing tool 2.7.12.0 Feb 11 2012 16:58:52
22:29:10.0046 3332 ============================================================
22:29:10.0046 3332 Current date / time: 2012/02/14 22:29:10.0046
22:29:10.0046 3332 SystemInfo:
22:29:10.0046 3332
22:29:10.0046 3332 OS Version: 5.1.2600 ServicePack: 2.0
22:29:10.0046 3332 Product type: Workstation
22:29:10.0046 3332 ComputerName: PAULE
22:29:10.0046 3332 UserName: Paulchen
22:29:10.0046 3332 Windows directory: C:\windows
22:29:10.0046 3332 System windows directory: C:\windows
22:29:10.0046 3332 Processor architecture: Intel x86
22:29:10.0046 3332 Number of processors: 1
22:29:10.0046 3332 Page size: 0x1000
22:29:10.0046 3332 Boot type: Normal boot
22:29:10.0046 3332 ============================================================
22:29:10.0734 3332 Drive \Device\Harddisk0\DR0 - Size: 0x3A70C60000 (233.76 Gb), SectorSize: 0x200, Cylinders: 0x7733, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000058
22:29:10.0750 3332 Drive \Device\Harddisk1\DR1 - Size: 0x262AE70000 (152.67 Gb), SectorSize: 0x200, Cylinders: 0x4DD9, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000058
22:29:10.0750 3332 Drive \Device\Harddisk2\DR9 - Size: 0x3D300000 (0.96 Gb), SectorSize: 0x200, Cylinders: 0x7C, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
22:29:10.0750 3332 \Device\Harddisk0\DR0:
22:29:10.0750 3332 MBR used
22:29:10.0750 3332 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x250F974
22:29:10.0859 3332 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x250F9F2, BlocksNum 0x1F2180
22:29:10.0859 3332 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x27116B5, BlocksNum 0x30E7639
22:29:10.0890 3332 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x57F8D2D, BlocksNum 0x1378FF8
22:29:10.0890 3332 \Device\Harddisk0\DR0\Partition4: MBR, Type 0x7, StartLBA 0x6B71D64, BlocksNum 0x4233762
22:29:10.0906 3332 \Device\Harddisk0\DR0\Partition5: MBR, Type 0x7, StartLBA 0xADA5505, BlocksNum 0x125DE26E
22:29:10.0906 3332 \Device\Harddisk1\DR1:
22:29:10.0906 3332 MBR used
22:29:10.0906 3332 \Device\Harddisk1\DR1\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x1314FF99
22:29:10.0906 3332 \Device\Harddisk2\DR9:
22:29:10.0906 3332 MBR used
22:29:10.0906 3332 \Device\Harddisk2\DR9\Partition0: MBR, Type 0x6, StartLBA 0x20, BlocksNum 0x1E97E0
22:29:11.0062 3332 Initialize success
22:29:11.0062 3332 ============================================================
22:29:14.0140 1180 ============================================================
22:29:14.0140 1180 Scan started
22:29:14.0140 1180 Mode: Manual;
22:29:14.0140 1180 ============================================================
22:29:14.0343 1180 A3AB (7d39b502a6cad1449b01b622c7ffce73) C:\windows\system32\DRIVERS\A3AB.sys
22:29:14.0343 1180 A3AB - ok
22:29:14.0406 1180 Abiosdsk - ok
22:29:14.0453 1180 abp480n5 - ok
22:29:14.0531 1180 ACPI (94b4741d2cf9ed38140b831293d1601a) C:\windows\system32\DRIVERS\ACPI.sys
22:29:14.0546 1180 ACPI - ok
22:29:14.0609 1180 ACPIEC (9e1ca3160dafb159ca14f83b1e317f75) C:\windows\system32\drivers\ACPIEC.sys
22:29:14.0609 1180 ACPIEC - ok
22:29:14.0687 1180 adfs (6d7f09cd92a9fef3a8efce66231fdd79) C:\windows\system32\drivers\adfs.sys
22:29:14.0703 1180 adfs - ok
22:29:14.0781 1180 adpu160m - ok
22:29:14.0859 1180 aec (841f385c6cfaf66b58fbd898722bb4f0) C:\windows\system32\drivers\aec.sys
22:29:14.0859 1180 aec - ok
22:29:14.0937 1180 AFD (5ac495f4cb807b2b98ad2ad591e6d92e) C:\windows\System32\drivers\afd.sys
22:29:14.0953 1180 AFD - ok
22:29:15.0000 1180 Aha154x - ok
22:29:15.0062 1180 aic78u2 - ok
22:29:15.0109 1180 aic78xx - ok
22:29:15.0203 1180 ALCXSENS (ba88534a3ceb6161e7432438b9ea4f54) C:\windows\system32\drivers\ALCXSENS.SYS
22:29:15.0203 1180 ALCXSENS - ok
22:29:15.0296 1180 ALCXWDM (9a6a99f0d75b457e3a2267776ebe9f47) C:\windows\system32\drivers\ALCXWDM.SYS
22:29:15.0296 1180 ALCXWDM - ok
22:29:15.0375 1180 AliIde - ok
22:29:15.0437 1180 amsint - ok
22:29:15.0515 1180 Arp1394 (f0d692b0bffb46e30eb3cea168bbc49f) C:\windows\system32\DRIVERS\arp1394.sys
22:29:15.0515 1180 Arp1394 - ok
22:29:15.0578 1180 asc - ok
22:29:15.0625 1180 asc3350p - ok
22:29:15.0687 1180 asc3550 - ok
22:29:15.0796 1180 AsyncMac (02000abf34af4c218c35d257024807d6) C:\windows\system32\DRIVERS\asyncmac.sys
22:29:15.0796 1180 AsyncMac - ok
22:29:15.0843 1180 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\windows\system32\DRIVERS\atapi.sys
22:29:15.0859 1180 atapi - ok
22:29:15.0921 1180 Atdisk - ok
22:29:16.0000 1180 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\windows\system32\DRIVERS\atmarpc.sys
22:29:16.0000 1180 Atmarpc - ok
22:29:16.0078 1180 audstub (d9f724aa26c010a217c97606b160ed68) C:\windows\system32\DRIVERS\audstub.sys
22:29:16.0078 1180 audstub - ok
22:29:16.0171 1180 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\windows\system32\drivers\Beep.sys
22:29:16.0171 1180 Beep - ok
22:29:16.0234 1180 catchme - ok
22:29:16.0312 1180 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\windows\system32\drivers\cbidf2k.sys
22:29:16.0312 1180 cbidf2k - ok
22:29:16.0390 1180 CCDECODE (6163ed60b684bab19d3352ab22fc48b2) C:\windows\system32\DRIVERS\CCDECODE.sys
22:29:16.0390 1180 CCDECODE - ok
22:29:16.0437 1180 cd20xrnt - ok
22:29:16.0515 1180 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\windows\system32\drivers\Cdaudio.sys
22:29:16.0515 1180 Cdaudio - ok
22:29:16.0562 1180 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\windows\system32\drivers\Cdfs.sys
22:29:16.0562 1180 Cdfs - ok
22:29:16.0625 1180 Cdrom (7b53584d94e9d8716b2de91d5f1cb42d) C:\windows\system32\DRIVERS\cdrom.sys
22:29:16.0625 1180 Cdrom - ok
22:29:16.0687 1180 Changer - ok
22:29:16.0796 1180 CmdIde - ok
22:29:16.0890 1180 Cpqarray - ok
22:29:16.0953 1180 dac2w2k - ok
22:29:17.0031 1180 dac960nt - ok
22:29:17.0109 1180 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\windows\system32\DRIVERS\disk.sys
22:29:17.0109 1180 Disk - ok
22:29:17.0218 1180 dmboot (5789b83ba87fc84c3568cf86cacef8ce) C:\windows\system32\drivers\dmboot.sys
22:29:17.0234 1180 dmboot - ok
22:29:17.0296 1180 dmio (084eb0a50a4f7b4705c8a57f234e5291) C:\windows\system32\drivers\dmio.sys
22:29:17.0296 1180 dmio - ok
22:29:17.0343 1180 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\windows\system32\drivers\dmload.sys
22:29:17.0343 1180 dmload - ok
22:29:17.0421 1180 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\windows\system32\drivers\DMusic.sys
22:29:17.0421 1180 DMusic - ok
22:29:17.0484 1180 dpti2o - ok
22:29:17.0546 1180 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\windows\system32\drivers\drmkaud.sys
22:29:17.0562 1180 drmkaud - ok
22:29:17.0625 1180 DumaNT (5b40d257176b7c1ed4367532c737e8a7) C:\windows\system32\DRIVERS\dumant.sys
22:29:17.0640 1180 DumaNT - ok
22:29:17.0734 1180 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\windows\system32\drivers\Fastfat.sys
22:29:17.0750 1180 Fastfat - ok
22:29:17.0812 1180 fasttx2k (3acbc73531dedd69837fe73b1623d49c) C:\windows\system32\DRIVERS\fasttx2k.sys
22:29:17.0812 1180 fasttx2k - ok
22:29:17.0906 1180 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\windows\system32\DRIVERS\fdc.sys
22:29:17.0906 1180 Fdc - ok
22:29:17.0953 1180 Fips (9e9af89f9b14aa6249065c309ce73bd8) C:\windows\system32\drivers\Fips.sys
22:29:17.0953 1180 Fips - ok
22:29:18.0140 1180 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\windows\system32\DRIVERS\flpydisk.sys
22:29:18.0171 1180 Flpydisk - ok
22:29:18.0312 1180 FltMgr (157754f0df355a9e0a6f54721914f9c6) C:\windows\system32\DRIVERS\fltMgr.sys
22:29:18.0312 1180 FltMgr - ok
22:29:18.0437 1180 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\windows\system32\drivers\Fs_Rec.sys
22:29:18.0437 1180 Fs_Rec - ok
22:29:18.0515 1180 Ftdisk (8f1955ce42e1484714b542f341647778) C:\windows\system32\DRIVERS\ftdisk.sys
22:29:18.0531 1180 Ftdisk - ok
22:29:18.0593 1180 gagp30kx (4216cd545e5c30807b560c5dcaa812e6) C:\windows\system32\DRIVERS\gagp30kx.sys
22:29:18.0593 1180 gagp30kx - ok
22:29:18.0625 1180 GMSIPCI - ok
22:29:18.0687 1180 Gpc (c0f1d4a21de5a415df8170616703debf) C:\windows\system32\DRIVERS\msgpc.sys
22:29:18.0687 1180 Gpc - ok
22:29:18.0812 1180 hidusb (1de6783b918f540149aa69943bdfeba8) C:\windows\system32\DRIVERS\hidusb.sys
22:29:18.0812 1180 hidusb - ok
22:29:18.0875 1180 hpn - ok
22:29:18.0953 1180 HPZid412 (30ca91e657cede2f95359d6ef186f650) C:\windows\system32\DRIVERS\HPZid412.sys
22:29:18.0953 1180 HPZid412 - ok
22:29:19.0015 1180 HPZipr12 (efd31afa752aa7c7bbb57bcbe2b01c78) C:\windows\system32\DRIVERS\HPZipr12.sys
22:29:19.0015 1180 HPZipr12 - ok
22:29:19.0109 1180 HPZius12 (7ac43c38ca8fd7ed0b0a4466f753e06e) C:\windows\system32\DRIVERS\HPZius12.sys
22:29:19.0109 1180 HPZius12 - ok
22:29:19.0171 1180 HTTP (c19b522a9ae0bbc3293397f3055e80a1) C:\windows\system32\Drivers\HTTP.sys
22:29:19.0187 1180 HTTP - ok
22:29:19.0234 1180 i2omgmt - ok
22:29:19.0296 1180 i2omp - ok
22:29:19.0375 1180 i8042prt (7c575018d0413440d75432a78b88c899) C:\windows\system32\DRIVERS\i8042prt.sys
22:29:19.0375 1180 i8042prt - ok
22:29:19.0437 1180 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\windows\system32\DRIVERS\imapi.sys
22:29:19.0437 1180 Imapi - ok
22:29:19.0515 1180 ini910u - ok
22:29:19.0578 1180 IntelIde - ok
22:29:19.0640 1180 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\windows\system32\DRIVERS\Ip6Fw.sys
22:29:19.0640 1180 Ip6Fw - ok
22:29:19.0703 1180 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\windows\system32\DRIVERS\ipfltdrv.sys
22:29:19.0703 1180 IpFilterDriver - ok
22:29:19.0781 1180 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\windows\system32\DRIVERS\ipinip.sys
22:29:19.0781 1180 IpInIp - ok
22:29:19.0843 1180 IpNat (b5a8e215ac29d24d60b4d1250ef05ace) C:\windows\system32\DRIVERS\ipnat.sys
22:29:19.0859 1180 IpNat - ok
22:29:19.0921 1180 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\windows\system32\DRIVERS\ipsec.sys
22:29:19.0937 1180 IPSec - ok
22:29:20.0000 1180 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\windows\system32\DRIVERS\irenum.sys
22:29:20.0000 1180 IRENUM - ok
22:29:20.0093 1180 isapnp (ce9b7afdf0a3d7dd8d1487262316b959) C:\windows\system32\DRIVERS\isapnp.sys
22:29:20.0093 1180 isapnp - ok
22:29:20.0187 1180 Kbdclass (b128fc0a5cd83f669d5de4b58f77c7d6) C:\windows\system32\DRIVERS\kbdclass.sys
22:29:20.0187 1180 Kbdclass - ok
22:29:20.0234 1180 kbdhid (7ec877aa899323b92874fe62c7ddcde7) C:\windows\system32\DRIVERS\kbdhid.sys
22:29:20.0234 1180 kbdhid - ok
22:29:20.0312 1180 kmixer (d93cad07c5683db066b0b2d2d3790ead) C:\windows\system32\drivers\kmixer.sys
22:29:20.0328 1180 kmixer - ok
22:29:20.0406 1180 KSecDD (eb7ffe87fd367ea8fca0506f74a87fbb) C:\windows\system32\drivers\KSecDD.sys
22:29:20.0421 1180 KSecDD - ok
22:29:20.0484 1180 lbrtfdc - ok
22:29:20.0609 1180 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\windows\system32\drivers\mnmdd.sys
22:29:20.0609 1180 mnmdd - ok
22:29:20.0687 1180 Modem (91a3da4b12f6f1d760463a7f7857f748) C:\windows\system32\drivers\Modem.sys
22:29:20.0687 1180 Modem - ok
22:29:20.0750 1180 Mouclass (71e15ca47fd947552054afb28536268f) C:\windows\system32\DRIVERS\mouclass.sys
22:29:20.0750 1180 Mouclass - ok
22:29:20.0812 1180 mouhid (66a6f73c74e1791464160a7065ce711a) C:\windows\system32\DRIVERS\mouhid.sys
22:29:20.0812 1180 mouhid - ok
22:29:20.0859 1180 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\windows\system32\drivers\MountMgr.sys
22:29:20.0859 1180 MountMgr - ok
22:29:20.0937 1180 mraid35x - ok
22:29:21.0000 1180 MRxDAV (46edcc8f2db2f322c24f48785cb46366) C:\windows\system32\DRIVERS\mrxdav.sys
22:29:21.0015 1180 MRxDAV - ok
22:29:21.0078 1180 MRxSmb (dacd0c212986591962ed782e8b742da0) C:\windows\system32\DRIVERS\mrxsmb.sys
22:29:21.0093 1180 MRxSmb ( Virus.Win32.ZAccess.g ) - infected
22:29:21.0093 1180 MRxSmb - detected Virus.Win32.ZAccess.g (0)
22:29:21.0171 1180 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\windows\system32\drivers\Msfs.sys
22:29:21.0171 1180 Msfs - ok
22:29:21.0187 1180 MSICPL - ok
22:29:21.0265 1180 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\windows\system32\drivers\MSKSSRV.sys
22:29:21.0265 1180 MSKSSRV - ok
22:29:21.0328 1180 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\windows\system32\drivers\MSPCLOCK.sys
22:29:21.0328 1180 MSPCLOCK - ok
22:29:21.0390 1180 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\windows\system32\drivers\MSPQM.sys
22:29:21.0390 1180 MSPQM - ok
22:29:21.0453 1180 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\windows\system32\DRIVERS\mssmbios.sys
22:29:21.0453 1180 mssmbios - ok
22:29:21.0515 1180 MSTEE (bf13612142995096ab084f2db7f40f77) C:\windows\system32\drivers\MSTEE.sys
22:29:21.0515 1180 MSTEE - ok
22:29:21.0562 1180 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\windows\system32\drivers\Mup.sys
22:29:21.0578 1180 Mup - ok
22:29:21.0625 1180 NABTSFEC (5c8dc6429c43dc6177c1fa5b76290d1a) C:\windows\system32\DRIVERS\NABTSFEC.sys
22:29:21.0640 1180 NABTSFEC - ok
22:29:21.0703 1180 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\windows\system32\drivers\NDIS.sys
22:29:21.0718 1180 NDIS - ok
22:29:21.0796 1180 NdisIP (520ce427a8b298f54112857bcf6bde15) C:\windows\system32\DRIVERS\NdisIP.sys
22:29:21.0796 1180 NdisIP - ok
22:29:21.0859 1180 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\windows\system32\DRIVERS\ndistapi.sys
22:29:21.0859 1180 NdisTapi - ok
22:29:21.0937 1180 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\windows\system32\DRIVERS\ndisuio.sys
22:29:21.0937 1180 Ndisuio - ok
22:29:21.0984 1180 NdisWan (0b90e255a9490166ab368cd55a529893) C:\windows\system32\DRIVERS\ndiswan.sys
22:29:22.0000 1180 NdisWan - ok
22:29:22.0062 1180 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\windows\system32\drivers\NDProxy.sys
22:29:22.0062 1180 NDProxy - ok
22:29:22.0125 1180 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\windows\system32\DRIVERS\netbios.sys
22:29:22.0125 1180 NetBIOS - ok
22:29:22.0171 1180 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\windows\system32\DRIVERS\netbt.sys
22:29:22.0187 1180 NetBT - ok
22:29:22.0312 1180 NIC1394 (5c5c53db4fef16cf87b9911c7e8c6fbc) C:\windows\system32\DRIVERS\nic1394.sys
22:29:22.0312 1180 NIC1394 - ok
22:29:22.0406 1180 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\windows\system32\drivers\Npfs.sys
22:29:22.0406 1180 Npfs - ok
22:29:22.0468 1180 Nsynas32 (4b4a21e158c039ee0888741bfe1d24e0) C:\windows\system32\drivers\Nsynas32.sys
22:29:22.0468 1180 Nsynas32 - ok
22:29:22.0484 1180 NTACCESS - ok
22:29:22.0546 1180 Ntfs (b78be402c3f63dd55521f73876951cdd) C:\windows\system32\drivers\Ntfs.sys
22:29:22.0562 1180 Ntfs - ok
22:29:22.0656 1180 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\windows\system32\drivers\Null.sys
22:29:22.0656 1180 Null - ok
22:29:22.0734 1180 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\windows\system32\DRIVERS\nwlnkflt.sys
22:29:22.0734 1180 NwlnkFlt - ok
22:29:22.0812 1180 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\windows\system32\DRIVERS\nwlnkfwd.sys
22:29:22.0812 1180 NwlnkFwd - ok
22:29:22.0859 1180 ohci1394 (0951db8e5823ea366b0e408d71e1ba2a) C:\windows\system32\DRIVERS\ohci1394.sys
22:29:22.0859 1180 ohci1394 - ok
22:29:22.0906 1180 Parport (b2f17a2edb5450e61973a037f63a595b) C:\windows\system32\DRIVERS\parport.sys
22:29:22.0921 1180 Parport - ok
22:29:22.0968 1180 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\windows\system32\drivers\PartMgr.sys
22:29:22.0968 1180 PartMgr - ok
22:29:23.0031 1180 ParVdm (c2bf987829099a3eaa2ca6a0a90ecb4f) C:\windows\system32\drivers\ParVdm.sys
22:29:23.0031 1180 ParVdm - ok
22:29:23.0078 1180 PCI (6fb463e5b243fbd6f3d3c83f914d94fb) C:\windows\system32\DRIVERS\pci.sys
22:29:23.0093 1180 PCI - ok
22:29:23.0140 1180 PCIDump - ok
22:29:23.0187 1180 PCIIde - ok
22:29:23.0296 1180 Pcmcia (e2363f4c1daff89abee5f593e13d8a05) C:\windows\system32\drivers\Pcmcia.sys
22:29:23.0296 1180 Pcmcia - ok
22:29:23.0359 1180 PDCOMP - ok
22:29:23.0406 1180 PDFRAME - ok
22:29:23.0468 1180 PDRELI - ok
22:29:23.0531 1180 PDRFRAME - ok
22:29:23.0593 1180 perc2 - ok
22:29:23.0640 1180 perc2hib - ok
22:29:23.0796 1180 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\windows\system32\DRIVERS\raspptp.sys
22:29:23.0796 1180 PptpMiniport - ok
22:29:23.0859 1180 PQNTDrv (4228630829c0e521c43d882a00533374) C:\windows\system32\drivers\PQNTDrv.sys
22:29:23.0859 1180 PQNTDrv - ok
22:29:23.0921 1180 Processor (3d7f196e77f986c106e9320b81a5ebbf) C:\windows\system32\DRIVERS\processr.sys
22:29:23.0921 1180 Processor - ok
22:29:23.0984 1180 Profos - ok
22:29:24.0062 1180 PSched (48671f327553dcf1d27f6197f622a668) C:\windows\system32\DRIVERS\psched.sys
22:29:24.0062 1180 PSched - ok
22:29:24.0125 1180 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\windows\system32\DRIVERS\ptilink.sys
22:29:24.0125 1180 Ptilink - ok
22:29:24.0187 1180 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\windows\system32\Drivers\PxHelp20.sys
22:29:24.0187 1180 PxHelp20 - ok
22:29:24.0250 1180 ql1080 - ok
22:29:24.0296 1180 Ql10wnt - ok
22:29:24.0359 1180 ql12160 - ok
22:29:24.0421 1180 ql1240 - ok
22:29:24.0468 1180 ql1280 - ok
22:29:24.0546 1180 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\windows\system32\DRIVERS\rasacd.sys
22:29:24.0546 1180 RasAcd - ok
22:29:24.0625 1180 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\windows\system32\DRIVERS\rasl2tp.sys
22:29:24.0625 1180 Rasl2tp - ok
22:29:24.0687 1180 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\windows\system32\DRIVERS\raspppoe.sys
22:29:24.0687 1180 RasPppoe - ok
22:29:24.0750 1180 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\windows\system32\DRIVERS\raspti.sys
22:29:24.0750 1180 Raspti - ok
22:29:24.0812 1180 Rdbss (29d66245adba878fff574cd66abd2884) C:\windows\system32\DRIVERS\rdbss.sys
22:29:24.0828 1180 Rdbss - ok
22:29:24.0875 1180 RDPCDD (4912d5b403614ce99c28420f75353332) C:\windows\system32\DRIVERS\RDPCDD.sys
22:29:24.0875 1180 RDPCDD - ok
22:29:24.0953 1180 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\windows\system32\DRIVERS\rdpdr.sys
22:29:24.0968 1180 rdpdr - ok
22:29:25.0031 1180 RDPWD (d4f5643d7714ef499ae9527fdcd50894) C:\windows\system32\drivers\RDPWD.sys
22:29:25.0046 1180 RDPWD - ok
22:29:25.0125 1180 redbook (aa56702e230860565cb8d43680f57f33) C:\windows\system32\DRIVERS\redbook.sys
22:29:25.0125 1180 redbook - ok
22:29:25.0296 1180 Secdrv (d26e26ea516450af9d072635c60387f4) C:\windows\system32\DRIVERS\secdrv.sys
22:29:25.0296 1180 Secdrv - ok
22:29:25.0390 1180 serenum (a2d868aeeff612e70e213c451a70cafb) C:\windows\system32\DRIVERS\serenum.sys
22:29:25.0390 1180 serenum - ok
22:29:25.0437 1180 Serial (cd5b9995afcdb466c9efc048d167e3be) C:\windows\system32\DRIVERS\serial.sys
22:29:25.0453 1180 Serial - ok
22:29:25.0500 1180 SetupNTGLM7X - ok
22:29:25.0546 1180 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\windows\system32\drivers\Sfloppy.sys
22:29:25.0546 1180 Sfloppy - ok
22:29:25.0640 1180 Simbad - ok
22:29:25.0703 1180 SLIP (5caeed86821fa2c6139e32e9e05ccdc9) C:\windows\system32\DRIVERS\SLIP.sys
22:29:25.0703 1180 SLIP - ok
22:29:25.0796 1180 SONYPVU1 (a1eceeaa5c5e74b2499eb51d38185b84) C:\windows\system32\DRIVERS\SONYPVU1.SYS
22:29:25.0796 1180 SONYPVU1 - ok
22:29:25.0859 1180 Sparrow - ok
22:29:25.0921 1180 splitter (8e186b8f23295d1e42c573b82b80d548) C:\windows\system32\drivers\splitter.sys
22:29:25.0921 1180 splitter - ok
22:29:25.0968 1180 sptd - ok
22:29:26.0046 1180 sr (e4200cb2f418d8fc4acdd7e38c419d6a) C:\windows\system32\DRIVERS\sr.sys
22:29:26.0062 1180 sr - ok
22:29:26.0140 1180 Srv (20b7e396720353e4117d64d9dcb926ca) C:\windows\system32\DRIVERS\srv.sys
22:29:26.0156 1180 Srv - ok
22:29:26.0218 1180 st3wolf - ok
22:29:26.0312 1180 streamip (284c57df5dc7abca656bc2b96a667afb) C:\windows\system32\DRIVERS\StreamIP.sys
22:29:26.0312 1180 streamip - ok
22:29:26.0359 1180 swenum (03c1bae4766e2450219d20b993d6e046) C:\windows\system32\DRIVERS\swenum.sys
22:29:26.0359 1180 swenum - ok
22:29:26.0421 1180 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\windows\system32\drivers\swmidi.sys
22:29:26.0421 1180 swmidi - ok
22:29:26.0484 1180 symc810 - ok
22:29:26.0546 1180 symc8xx - ok
22:29:26.0593 1180 sym_hi - ok
22:29:26.0656 1180 sym_u3 - ok
22:29:26.0718 1180 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\windows\system32\drivers\sysaudio.sys
22:29:26.0718 1180 sysaudio - ok
22:29:26.0796 1180 Tcpip (9f4b36614a0fc234525ba224957de55c) C:\windows\system32\DRIVERS\tcpip.sys
22:29:26.0828 1180 Tcpip - ok
22:29:26.0890 1180 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\windows\system32\drivers\TDPIPE.sys
22:29:26.0890 1180 TDPIPE - ok
22:29:26.0968 1180 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\windows\system32\drivers\TDTCP.sys
22:29:26.0968 1180 TDTCP - ok
22:29:27.0046 1180 TermDD (a540a99c281d933f3d69d55e48727f47) C:\windows\system32\DRIVERS\termdd.sys
22:29:27.0046 1180 TermDD - ok
22:29:27.0140 1180 TosIde - ok
22:29:27.0171 1180 Trufos - ok
22:29:27.0265 1180 TuneUpUtilitiesDrv (f2107c9d85ec0df116939ccce06ae697) C:\Programme\TuneUp Utilities 2012\TuneUpUtilitiesDriver32.sys
22:29:27.0265 1180 TuneUpUtilitiesDrv - ok
22:29:27.0328 1180 TVICHW32 (e266683fc95abdec17cd378564e1b54b) C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS
22:29:27.0328 1180 TVICHW32 - ok
22:29:27.0406 1180 Udfs (12f70256f140cd7d52c58c7048fde657) C:\windows\system32\drivers\Udfs.sys
22:29:27.0421 1180 Udfs - ok
22:29:27.0453 1180 ultra - ok
22:29:27.0546 1180 Update (aff2e5045961bbc0a602bb6f95eb1345) C:\windows\system32\DRIVERS\update.sys
22:29:27.0546 1180 Update - ok
22:29:27.0656 1180 usbaudio (45a0d14b26c35497ad93bce7e15c9941) C:\windows\system32\drivers\usbaudio.sys
22:29:27.0656 1180 usbaudio - ok
22:29:27.0703 1180 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\windows\system32\DRIVERS\usbccgp.sys
22:29:27.0703 1180 usbccgp - ok
22:29:27.0765 1180 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\windows\system32\DRIVERS\usbehci.sys
22:29:27.0765 1180 usbehci - ok
22:29:27.0828 1180 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\windows\system32\DRIVERS\usbhub.sys
22:29:27.0828 1180 usbhub - ok
22:29:27.0875 1180 usbprint (a42369b7cd8886cd7c70f33da6fcbcf5) C:\windows\system32\DRIVERS\usbprint.sys
22:29:27.0875 1180 usbprint - ok
22:29:27.0937 1180 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\windows\system32\DRIVERS\usbscan.sys
22:29:27.0937 1180 usbscan - ok
22:29:28.0031 1180 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\windows\system32\DRIVERS\USBSTOR.SYS
22:29:28.0031 1180 USBSTOR - ok
22:29:28.0093 1180 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\windows\system32\DRIVERS\usbuhci.sys
22:29:28.0093 1180 usbuhci - ok
22:29:28.0171 1180 usbvideo (8968ff3973a883c49e8b564200f565b9) C:\windows\system32\Drivers\usbvideo.sys
22:29:28.0171 1180 usbvideo - ok
22:29:28.0234 1180 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\windows\System32\drivers\vga.sys
22:29:28.0234 1180 VgaSave - ok
22:29:28.0312 1180 viaagp1 (4b039bbd037b01f5db5a144c837f283a) C:\windows\system32\DRIVERS\viaagp1.sys
22:29:28.0312 1180 viaagp1 - ok
22:29:28.0375 1180 ViaIde (59cb1338ad3654417bea49636457f65d) C:\windows\system32\DRIVERS\viaide.sys
22:29:28.0375 1180 ViaIde - ok
22:29:28.0421 1180 viasraid (ebe101c01d80a42868f57b327be1b564) C:\windows\system32\drivers\viasraid.sys
22:29:28.0421 1180 viasraid - ok
22:29:28.0484 1180 VolSnap (d6888520ff56d72a50437e371ca25fc9) C:\windows\system32\drivers\VolSnap.sys
22:29:28.0500 1180 VolSnap - ok
22:29:28.0609 1180 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\windows\system32\DRIVERS\wanarp.sys
22:29:28.0609 1180 Wanarp - ok
22:29:28.0656 1180 WDICA - ok
22:29:28.0750 1180 wdmaud (2797f33ebf50466020c430ee4f037933) C:\windows\system32\drivers\wdmaud.sys
22:29:28.0781 1180 wdmaud - ok
22:29:28.0968 1180 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\windows\System32\drivers\ws2ifsl.sys
22:29:28.0968 1180 WS2IFSL - ok
22:29:29.0062 1180 WSTCODEC (d5842484f05e12121c511aa93f6439ec) C:\windows\system32\DRIVERS\WSTCODEC.SYS
22:29:29.0062 1180 WSTCODEC - ok
22:29:29.0171 1180 yukonwxp (a8d429e2268792638cffc57552c5e736) C:\windows\system32\DRIVERS\yk51x86.sys
22:29:29.0187 1180 yukonwxp - ok
22:29:29.0250 1180 MBR (0x1B8) (72b8ce41af0de751c946802b3ed844b4) \Device\Harddisk0\DR0
22:29:29.0375 1180 \Device\Harddisk0\DR0 - ok
22:29:29.0406 1180 MBR (0x1B8) (72b8ce41af0de751c946802b3ed844b4) \Device\Harddisk1\DR1
22:29:29.0468 1180 \Device\Harddisk1\DR1 - ok
22:29:29.0500 1180 MBR (0x1B8) (973e9ba32fdbb305c552ed3e1ebf0686) \Device\Harddisk2\DR9
22:29:32.0171 1180 \Device\Harddisk2\DR9 - ok
22:29:32.0218 1180 Boot (0x1200) (d1ac8538efb1f600ec71f7ccea922994) \Device\Harddisk0\DR0\Partition0
22:29:32.0218 1180 \Device\Harddisk0\DR0\Partition0 - ok
22:29:32.0250 1180 Boot (0x1200) (b7ccd62c93a12faeb9c70f5194612a7b) \Device\Harddisk0\DR0\Partition1
22:29:32.0250 1180 \Device\Harddisk0\DR0\Partition1 - ok
22:29:32.0296 1180 Boot (0x1200) (a7507a9c2eca0f0efff7ee5a3949c8be) \Device\Harddisk0\DR0\Partition2
22:29:32.0296 1180 \Device\Harddisk0\DR0\Partition2 - ok
22:29:32.0328 1180 Boot (0x1200) (5019e1c7c6f5401039a4f09b4acba773) \Device\Harddisk0\DR0\Partition3
22:29:32.0328 1180 \Device\Harddisk0\DR0\Partition3 - ok
22:29:32.0359 1180 Boot (0x1200) (b984e0e5be4bb9fb3212d249c468240d) \Device\Harddisk0\DR0\Partition4
22:29:32.0359 1180 \Device\Harddisk0\DR0\Partition4 - ok
22:29:32.0390 1180 Boot (0x1200) (286b55e0895c9c6959423c285df10501) \Device\Harddisk0\DR0\Partition5
22:29:32.0390 1180 \Device\Harddisk0\DR0\Partition5 - ok
22:29:32.0406 1180 Boot (0x1200) (1cdcab632fc09acca9d9fc62ab1eaa90) \Device\Harddisk1\DR1\Partition0
22:29:32.0406 1180 \Device\Harddisk1\DR1\Partition0 - ok
22:29:32.0437 1180 Boot (0x1200) (4897900b3194ab0160b4c2f6b7220070) \Device\Harddisk2\DR9\Partition0
22:29:32.0437 1180 \Device\Harddisk2\DR9\Partition0 - ok
22:29:32.0437 1180 ============================================================
22:29:32.0437 1180 Scan finished
22:29:32.0437 1180 ============================================================
22:29:32.0484 3468 Detected object count: 1
22:29:32.0484 3468 Actual detected object count: 1
22:29:50.0812 3468 C:\windows\system32\DRIVERS\mrxsmb.sys - copied to quarantine
22:29:50.0859 3468 VerifyFileNameVersionInfo: GetFileVersionInfoSizeW(C:\windows\system32\drivers\mrxsmb.sys) error 1813
22:29:52.0031 3468 Backup copy found, using it..
22:29:52.0046 3468 C:\windows\system32\DRIVERS\mrxsmb.sys - will be cured on reboot
22:29:54.0828 3468 MRxSmb ( Virus.Win32.ZAccess.g ) - User select action: Cure
22:30:12.0296 0176 Deinitialize success und noch den Combofix.log: Code:
ComboFix 12-02-13.01 - Paulchen 14.02.2012 22:52:15.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.49.1031.18.1023.761 [GMT 1:00]
ausgeführt von:: c:\dokumente und einstellungen\Paulchen.PAULE\Eigene Dateien\Downloads\ComboFix.exe
.
Achtung - Auf diesem PC ist keine Wiederherstellungskonsole installiert !!
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Infizierte Kopie von c:\windows\system32\msgsvc.dll wurde gefunden und desinfiziert
Kopie von - c:\windows\ERDNT\cache\msgsvc.dll wurde wiederhergestellt
.
.
((((((((((((((((((((((( Dateien erstellt von 2012-01-14 bis 2012-02-14 ))))))))))))))))))))))))))))))
.
.
2012-02-14 21:29 . 2012-02-14 21:29 -------- d-----w- C:\TDSSKiller_Quarantine
2012-02-11 13:51 . 2012-02-11 13:51 -------- d-----w- c:\dokumente und einstellungen\Paulchen.PAULE\Lokale Einstellungen\Anwendungsdaten\Microsoft Corporation
2012-02-11 09:13 . 2012-02-11 09:13 -------- d-----w- c:\dokumente und einstellungen\Administrator.PAULE\Lokale Einstellungen\Anwendungsdaten\Google
2012-02-09 21:23 . 2012-02-09 21:23 -------- d-----w- c:\programme\7-Zip
2012-02-09 09:34 . 2012-02-09 09:35 -------- d-----w- C:\FRST
2012-02-08 21:02 . 2012-02-08 21:02 -------- d-----w- c:\dokumente und einstellungen\Administrator.PAULE\Anwendungsdaten\TrojanHunter
2012-02-08 20:59 . 2010-08-19 18:22 409600 ----a-w- c:\programme\Mozilla Firefox\Kaspersky Rescue2Usb\rescue2usb.exe
2012-02-08 20:59 . 2010-04-01 10:01 28160 ----a-w- c:\programme\Mozilla Firefox\Kaspersky Rescue2Usb\syslinux.exe
2012-02-08 20:59 . 2009-10-16 15:43 237849 ----a-w- c:\programme\Mozilla Firefox\Kaspersky Rescue2Usb\grub.exe
2012-02-08 20:09 . 2012-02-08 22:23 -------- d-----w- c:\programme\TrojanHunter 5.5
2012-02-08 19:30 . 2012-02-08 21:07 -------- d-----w- c:\programme\PC Tools Security
2012-02-08 19:14 . 2012-02-08 20:07 -------- d-----w- c:\dokumente und einstellungen\All Users.WINDOWS\Anwendungsdaten\PC Tools
2012-02-08 18:41 . 2012-02-08 18:41 -------- d-s---w- c:\dokumente und einstellungen\Administrator.PAULE\UserData
2012-02-08 18:41 . 2012-02-09 09:40 -------- d-----r- c:\dokumente und einstellungen\Administrator.PAULE\Eigene Dateien
2012-02-08 15:54 . 2012-02-08 15:55 -------- d-----w- c:\dokumente und einstellungen\Administrator.PAULE\Lokale Einstellungen\Anwendungsdaten\Adobe
2012-02-08 15:43 . 2012-02-08 16:00 -------- d-----w- c:\windows\system32\CatRoot_bak
2012-02-06 10:12 . 2012-02-06 10:12 -------- d-s---w- c:\dokumente und einstellungen\LocalService.NT-AUTORITÄT.000\UserData
2012-02-06 09:38 . 2012-02-09 09:38 0 --sha-w- c:\windows\system32\dds_log_trash.cmd
2012-01-24 12:57 . 2012-01-24 12:57 -------- d-----w- c:\dokumente und einstellungen\Administrator.PAULE\Anwendungsdaten\Corel
2012-01-24 12:51 . 2012-01-24 12:51 -------- d-----w- c:\dokumente und einstellungen\Administrator.PAULE\Anwendungsdaten\TuneUp Software
2012-01-24 12:50 . 2012-01-24 12:50 -------- d-----w- c:\dokumente und einstellungen\Administrator.PAULE\Lokale Einstellungen\Anwendungsdaten\Mozilla
2012-01-22 13:15 . 2012-01-22 13:15 -------- d-----w- c:\dokumente und einstellungen\Paulchen.PAULE\Anwendungsdaten\PopCapv1003
2012-01-22 13:03 . 2012-01-22 13:03 -------- d-----w- c:\dokumente und einstellungen\Paulchen.PAULE\Lokale Einstellungen\Anwendungsdaten\AresXZ
2012-01-22 12:59 . 2012-01-22 13:04 -------- d-----w- c:\dokumente und einstellungen\Paulchen.PAULE\Anwendungsdaten\LimeRunner
2012-01-22 12:55 . 2012-02-11 12:43 -------- d-sh--w- c:\dokumente und einstellungen\Paulchen.PAULE\Lokale Einstellungen\Anwendungsdaten\73c07115
2012-01-21 20:49 . 2012-01-21 20:49 -------- d-----w- c:\dokumente und einstellungen\Paulchen.PAULE\Anwendungsdaten\SpinTop Games
2012-01-21 20:49 . 2012-01-21 20:49 -------- d-----w- c:\dokumente und einstellungen\All Users.WINDOWS\Anwendungsdaten\PopCapY
2012-01-21 20:49 . 2012-01-21 20:49 -------- d-----w- c:\dokumente und einstellungen\All Users.WINDOWS\Anwendungsdaten\934bcbfe-35c5-4039-88e2-8d1494de198e
2012-01-21 20:48 . 2012-01-21 20:48 -------- d-----w- C:\DOCUME~1
2012-01-21 09:08 . 2012-01-21 09:08 418304 ----a-w- c:\dokumente und einstellungen\Paulchen.PAULE\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\TischR.exe
2012-01-21 08:42 . 2012-01-21 08:42 -------- d-----w- c:\dokumente und einstellungen\LocalService.NT-AUTORITÄT.000\Anwendungsdaten\TuneUp Software
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-30 10:33 . 2011-05-13 04:59 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-14 11:23 . 2012-01-05 19:04 31552 ----a-w- c:\windows\system32\TURegOpt.exe
2012-02-14 20:48 . 2011-05-11 18:25 134104 ----a-w- c:\programme\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-02-11_12.51.45 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-02-14 21:51 . 2012-02-14 21:51 16384 c:\windows\Temp\Perflib_Perfdata_738.dat
+ 2012-02-14 21:59 . 2012-02-14 21:59 16384 c:\windows\Temp\Perflib_Perfdata_6f8.dat
+ 2012-02-14 21:59 . 2012-02-14 21:59 16384 c:\windows\Temp\Perflib_Perfdata_6ac.dat
+ 2012-02-08 16:01 . 2012-02-14 21:31 451456 c:\windows\system32\drivers\mrxsmb.sys
- 2012-02-08 16:01 . 2002-12-31 12:00 451456 c:\windows\system32\drivers\mrxsmb.sys
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Duden Korrektor SysTray"="c:\programme\Duden\Duden Korrektor\DKtray.exe" [2009-05-06 611024]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ptipbmf"="ptipbmf.dll" [2003-06-20 118784]
"ISUSPM Startup"="c:\progra~1\GEMEIN~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-08-09 221184]
"ISUSScheduler"="c:\programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe" [2004-08-09 81920]
"Acrobat Assistant 7.0"="f:\adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 483328]
"SunJavaUpdateSched"="c:\programme\Gemeinsame Dateien\Java\Java Update\jusched.exe" [2010-05-14 248552]
"CanonMyPrinter"="c:\programme\Canon\MyPrinter\BJMyPrt.exe" [2009-07-07 1848648]
"AdobeCS4ServiceManager"="c:\programme\Gemeinsame Dateien\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2002-12-31 15360]
.
c:\dokumente und einstellungen\Los gehts\Startmenü\Programme\Autostart\
Adobe Gamma.lnk - c:\programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
.
[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1 (0x1)
.
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users.WINDOWS^Startmenü^Programme^Autostart^Adobe Acrobat - Schnellstart.lnk]
backup=c:\windows\pss\Adobe Acrobat - Schnellstart.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users.WINDOWS^Startmenü^Programme^Autostart^Adobe Acrobat Speed Launcher.lnk]
backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users.WINDOWS^Startmenü^Programme^Autostart^HP Digital Imaging Monitor.lnk]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users.WINDOWS^Startmenü^Programme^Autostart^WISO Mein Sparbuch heute.lnk]
backup=c:\windows\pss\WISO Mein Sparbuch heute.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2006-02-19 00:41 49152 ----a-w- c:\programme\HP\HP Software Update\hpwuSchd2.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programme\\fotobuch.de\\Designer 2.0\\Designer.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Programme\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Programme\\Winamp\\winamp.exe"=
"c:\\Dokumente und Einstellungen\\Paulchen.PAULE\\Lokale Einstellungen\\Anwendungsdaten\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Programme\\Gemeinsame Dateien\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Programme\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Programme\\Mozilla Firefox\\firefox.exe"=
"c:\\Programme\\Google\\Picasa3\\Picasa3.exe"=
"c:\\Programme\\Google\\Picasa3\\PicasaUpdater.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"5353:TCP"= 5353:TCP:Adobe CSI CS4
.
R0 viasraid;viasraid;c:\windows\system32\drivers\viasraid.sys [12.12.2003 16:49 77312]
R2 AAV UpdateService;AAV UpdateService;c:\programme\Gemeinsame Dateien\AAV\aavus.exe [04.10.2007 14:32 122880]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\programme\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe [14.12.2011 12:23 1514304]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\programme\TuneUp Utilities 2012\TuneUpUtilitiesDriver32.sys [12.12.2011 19:31 10064]
S2 gupdate;Google Update Service (gupdate);c:\programme\Google\Update\GoogleUpdate.exe [09.11.2010 21:42 136176]
S3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\drivers\A3AB.sys [02.09.2004 20:01 396480]
S3 gupdatem;Google Update-Dienst (gupdatem);c:\programme\Google\Update\GoogleUpdate.exe [09.11.2010 21:42 136176]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\h:\ntglm7x.sys --> h:\NTGLM7X.sys [?]
S3 st3wolf;st3wolf;c:\windows\system32\DRIVERS\st3wolf.sys --> c:\windows\system32\DRIVERS\st3wolf.sys [?]
S3 SXDS10;soft Xpansion Dispatch Service;c:\programme\Gemeinsame Dateien\soft Xpansion\SXDS10.exe [08.11.2010 01:16 149504]
S4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys --> c:\windows\system32\Drivers\sptd.sys [?]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
U3sHlpDr
ATIBTXBAR
xcomm
s616obex
HIDSwvd
ScFBPNT2
pmounter
tmmbd
vmkbd
tmesrv3
incdrm
REVO
CiscoVpnInstallService
ESMCR
bcoreusb
slee_503_service
CrystalSysInfo
vmnetadapter
pnkbstrk
MTDVC2
s125bus
se45mdm
plsremotesvc
acdpowerservice
mi-raysat_3dsmax9_32
vpcnets2
SE27mdfl
downloadmanagerlite
SaiNtHid
rampartsvc
areschatserver
backupexecrpcservice
wltwo51b
hsf_msft
PXRDDriver
athr
AeLookupSvc
Pctspk
aiclient
sr_service
ccevtmgr
clnt_clientman
pfc
DSXUSB
papycpu2
vulfnths
UimBus
ndassvc
ltck000c
CAM1210
ltxred
cvslock
dxdebug
icepack
SPFDRV
pdfcreatormessages
HWIONT
tfsnudfa
AVerTV
awhost32
RESMGR
RioS30
purendis
vmnetdhcp
nmwcdcj
ati2mtaa
uleadburninghelper
nsm1bus
avg7rsxp
mafwboot
tpkd
websenserealtimeanalyzer
vncdrv
SprintRcAppSvc
KLOGNT
mwsarcpkt
atchksrv
tifsfilter
CTEDSPFX.DLL
WUSB54Gv4SVC
pop3d32
uphclean
PGPdisk
mcmispupdmgr
GBDevice
ZSMC211
mindretrieve
fax
ssm_mdfl
transarcafsdaemon
RR2Ctrl
pvservice
cachemanxp
viagfx
e1express
webrootspysweeperservice
jsdaemon
w550mdm
DellAMBrokerService
lyncusbserv
epsonbidirectionalservice
pcampr5
pctavsvc
RTL8169
LVBulk
bcm43xx
Appn
pavagente
vmauthdservice
pmem
id2scaps
s3psddr
websensecamserver
mpservice
fallback
wg4n
tdrpman
vet-rec
acs
bgmainsvc
freepops
SWUMX51
wampapache
smbusp
mcmscsvc
oracleservicesecinst
Packet
se59obex
rpaservice
ZSMC301b
AKSIFDH
mqdmmdfl
cidaemon
SPCtl
defwatch
radclock
se26unic
MobilityService
InCDsrvR
avgmfx86
lktimesync
atmeltpm
co_mon
ezplay
ctdvda2k
slssvc
winpower
se58bus
ndiscm
transactional
lxce_device
sf
prevxdriver
slave
viaagp
rspndr
RushTopDevice
upsmonservice
o2flash
nipsvc
utilman
btwdndis
ipssvc
riomsc
pdlndqll
qbcfmonitorservice
sonypvs1
smcirda
crystalinputfileserver
PCDCODEC
v124
aswtdi
Ndismeetro
ASFWHide
omnidrv
cmudau
MRESP50a64
SSHDRV61
aclient
mwlsvc
BASFND
ultra66
rasirda
NxNetMon
qfcoresvc
nvport
MxlW2k
WUSB54GPV4SRV
nwrdr
vaiomediaplatform-integratedserver-upnp
blueletscoaudio
aslm75
fah@c:+fah+fah-service+fah502-console.exe
pdlnemsg
sfvfs02
NMSSvc
atfsd
wlsetupsvc
aavmker4
NWSLP
SPLITCAM
pavfnsvr
tpsrv
screadspool
ELkbd
regdefend
ifp800
agpcpq
elbycdio
Sunkfiltp
forcewarewebinterface
hidbatt
lsdiorw
OEM02Dev
gearsecurity
exfat
UMAXPCLS
oracle_load_balancer_60_client-forms6i
zpnodecollector
nmservice
PTDCBus
nimcdlbk
SWNC5E00
lxcg_device
ZuneWlanCfgSvc
U81xobex
oracle_load_balancer_60_client-forms6ip9
upperdev
se2End5
retinaengine
AlKernel
RR2IOMod
WmHidLo
se58unic
F700iat
oraclesnmppeerencapsulator
sysmgmthp
NWSIPX32
iftpsvc
s217mdfl
usb20l
n3900
SNP2STD
tunmp
Via4in1
teefer2
TuneUp.Defrag
elagopro
ROB_A
dlaopiom
mdvrmng
vetefile
elnkfwppservice
hsvcmod
client32
winvnc
siside
NWUSBPort
ipodsrv
hpwirelessmgr
GBFSHook
unrealircd
pavreport
eabusb
dnsexit
mhndrv
SrvcEPECioctl
s716mdm
dot4ufd
tvald
kbfiltr
arrayssl_vpn_service3,0,1,9
cm102u32
pdlndlpb
NVR0FLASHDev
ALABULK
vusbbus
nvcap
netrcacm
A4S2600
rdnaoflsvc
sthda
BcmSqlStartupSvc
caboagp
tossmbnt
bt
lexbces
bt3cser
spsslm
fsdfwd
vstor2
bthmodem
SiS7018
EAWDMFD
tbhsd
emitray
navapsvc
apphostsvc
pnkbstrb
XBCD
USB11LDR
SRTSP
NtMtlFax
QWAVE
AmdLLD
DKbFltr
tmactmon
KR10I
bthidenum
cvsnt
steamdvr
Defrag32
imagedrv
nocashio
lxda_device
Blfp
CoolerXPDriver
ccsetmgr
sfusvc
ssm_bus
windrvNT
syslogd
aamqdispatcher
avsvcmonitor
nmwcd
apache
LMouKE
ahcix86s
stirusb
dlcq_device
rnadirectory
w810bus
aswupdsv
webrootcommagentservice
cdrbsvsd
s217mdm
arc
carboncopyscheduler
sscdmdfl
CX88ENC
pca
TIEHDUSB
schscnt
SE27obex
RDID1027
NuidFltr
EIO
ma_cmidi_installerservice
mbackmonitor
SRS_SSCFilter
akshhl
Tablet2k
AcronisOSSReinstallSvc
ql2100
SlWdmSup
videX32
ownershipprotocol
inort
imagesrv
flutilssvc
rtl8139
SMTPSVC
Mtlstrm
nvrd64
GT891x
bgsvcgen
LCcfltr
nimdbgk
ctprxy2k
3comtftp
PTDCVsp
ssfs0509
Slntamr
cicssfs.scmmc223
StickyMesger
vaiomediaplatform-mobile-gateway
ltmodem5
wkscfgsrv
SiS300i
winss
mcupdmgr.exe
remoterecord
pcdrndisuio
ntcharge
vsapint
oracle_load_balancer_60_server-forms6i
sglfb
VMAUDIO
zumbus
trayman
nm
sbcssvc
hap16v2k
s125obex
DevUpper
lxbx_device
ssoftservice
DCamUSBGrandTek
dcevt32
NWSNS
k56
VRFIL
lvhidsvc
cbidf
dpc_srv_webcast
risdptsk
cwafadminmonitor
CcmExec
vvdsvc
GV600_4
dnserver32
mferkdk
WSIMD
symndis
dns4meclient
XAudio
z800bus
W700mdfl
wpshelper
s3savagemx
cmuda3
rt61
avidstartup
df5serv
SQLWriter
EQDRV5
lusbaudio
flashcom
tfsndres
szkg
epfwtdi
tversitymediaserver
qbposdbservices
ino_flpy
rvsinst
stllssvr
Xyz777b
ivscheduler
ac97intc
se59mdm
cics.region2
ZD1211BU(ZyDAS)
bt3cusb
winpowermanager
WinDriver6
lhidflt2
etoksrv
SetupSys
tmlisten
upnp
BrUsbSer
GameConsoleService
dlcj_device
KR3NPXP
ICAM3NT5
VCAM
ccflic0
deventagent
USB28xxBGA
cportclm
oracle_load_balancer_60_client-forms6ip14
rslinxng
cics.region1
RIOXDRV
PGPsdkDriver
ngdbserv
aliadwdm
SIODRV
twotrack
IBMTPCHK
vulfntrs
elbydelay
FsVga
fsaa
FirePM
Memctl
lxdmCATSCustConnectService
jobserver_report
mcp
nimcrpcsu
QV2KUX
MRENDIS5
SE27bus
wudfsvc
modemcsa
vetmsgnt
mcnasvc
smcservice
idechndr
Cam5607
nscservice
eabfiltr
pdiddcci
Sk9920nt
psdistributionagent
avfilter
cavasm
raysat3_4_6_18server
qcmerced
lxbs_device
cpsvc
crystalaps
matlabserver
fasttraksvc
cxusb
tvalz
obvious
tiumfwl
gs30s
ispwdsvc
lxbt_device
vcsw
epsonstatusagent2
a016obex
SGHIDI
motmodem
mstdfrgs
richvideo
ftpqueue
outpostfirewall
USBVCD
tng-doba
VRADFIL
CTMMOUNT
se58mgmt
webfilter
StMp3Rec
pcx1unic
oracleorahomepagingserver
SE26mdfl
TNaviSrv
VNUSB
VC4CB104
acrotray
SrvcSSIOMngr
hap17v2k
SndTDriverV32
hidir
Cam5603D
usbvm321
avhook
TPECioCtl
websenseuserservice
ctusfsyn
SE26obex
SeratoUsb
mssqlserver
Evian
pdlndsdl
tappsrv
ntsyslog
z800obex
s116mdfl
xfilt
msk80service
Wdf01000
pdlnacom
mdc8021x
a8djavs
btwhid
3c1807pd
pdagent
belmonitorservice
symantecantibotagent
gotomypc
w300mdm
InterBaseGuardian
lockmgr
webupdate
earthlinksafeconnectagent
ctaud2k
wap3gx
w200mdfl
pcx1nd5
T6963C
AmeLanPc
hsf_dpv
akshasp
icam4usb
eloggersvc6
sfdrv01
BLKWGU(Belkin)
admservice
TPPWRIF
elbycdfl
intelroam
ggsemc
Uim_IM
ehrecvr
FreeTdi
arcltsrv
GcKernel
Alpham1
Tb2RCAssist
btfirst
LMIRfsClientNP
senfilt
CE3
USBAAPL
cwafeventrouter
tavsvc
s716mgmt
svv
FontCache3.0.0.0.
GoBack2K
pxfhmdm
fshttps
ageresoftmodem
scdemu
bjmcmng
rbfilter
mcdbus
cxlpt
HpqRemHid
w22n51
fsks
eectrl
k750mgmt
klif
BrSerIf
SenFiltService
filechecker
WLAN_USB
tdsmapi
lcs
msmpsvc
vci
pcidrv
as32svc
aw_host
nettcpportsharing
NWFILTER
nscirda
stunnel
NCPro
SE2Emdfl
RVIEG01
plscsi
SecureStorageService
issuser
websensepolicyserver
tsp
VAIOMediaPlatform-MusicServer-UPnP
UsbserFilt
WGX
tvtnetwk
enecbpth
nvpvrmon
brmfrmps
RR2Mjpeg
UlSata
utscsi
.
Inhalt des "geplante Tasks" Ordners
.
2012-02-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programme\Google\Update\GoogleUpdate.exe [2010-11-09 20:42]
.
2012-02-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programme\Google\Update\GoogleUpdate.exe [2010-11-09 20:42]
.
2012-02-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-616249376-839522115-1003Core.job
- c:\dokumente und einstellungen\Paulchen.PAULE\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe [2011-07-12 12:37]
.
2012-02-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-616249376-839522115-1003UA.job
- c:\dokumente und einstellungen\Paulchen.PAULE\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe [2011-07-12 12:37]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.google.de/
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Convert link target to Adobe PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\dokumente und einstellungen\Paulchen.PAULE\Anwendungsdaten\Mozilla\Firefox\Profiles\fhjkjkdq.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?hl=de
FF - prefs.js: network.proxy.type - 0
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
SafeBoot-36897956.sys
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2012-02-14 22:59
Windows 5.1.2600 Service Pack 2 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\System\ControlSet002\Enum\LPTENUM\KyoceraFS-1700\5&1d62032d&0&LPT1.4]
@Denied: (C D) (Everyone)
"DeviceDesc"="Kyocera FS-1700"
"LocationInformation"="LPT1.4"
"Capabilities"=dword:00000040
"ConfigFlags"=dword:00000000
"HardwareID"=multi:"LPTENUM\\KyoceraFS-17000C08\00KyoceraFS-17000C08\00\00"
"ClassGUID"="{4D36E979-E325-11CE-BFC1-08002BE10318}"
"Class"="Printer"
"Driver"="{4D36E979-E325-11CE-BFC1-08002BE10318}\\0001"
"Mfg"="Kyocera Mita"
.
[HKEY_LOCAL_MACHINE\System\ControlSet002\Enum\PCIIDE]
@DACL=(02 0000)
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'winlogon.exe'(712)
c:\programme\Gemeinsame Dateien\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
- - - - - - - > 'explorer.exe'(892)
c:\windows\system32\msi.dll
c:\programme\Gemeinsame Dateien\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\programme\Java\jre6\bin\jqs.exe
c:\windows\system32\HPZipm12.exe
c:\windows\System32\snmp.exe
c:\windows\system32\wdfmgr.exe
c:\programme\Canon\CAL\CALMAIN.exe
c:\programme\Duden\Duden Korrektor\DKCore.exe
c:\programme\Office-Bibliothek\officebib.exe
c:\programme\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe
c:\windows\system32\wscntfy.exe
c:\programme\Gemeinsame Dateien\Java\Java Update\jucheck.exe
c:\windows\system32\taskmgr.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-02-14 23:12:10 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2012-02-14 22:12
ComboFix2.txt 2012-02-11 13:05
.
Vor Suchlauf: 7.832.342.528 Bytes frei
Nach Suchlauf: 7.841.898.496 Bytes frei
.
- - End Of File - - CA7BE4BA646BA4CBCF1226761B6B47BF |