So, hier der Combofix Log.
Combofix Logfile: Code:
ComboFix 10-06-13.04 - Hendrik 14.06.2010 14:41:10.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.3070.1618 [GMT 2:00]
ausgeführt von:: c:\users\Hendrik\Desktop\cofi.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\Hendrik\AppData\Roaming\Desktopicon
c:\users\Hendrik\AppData\Roaming\Desktopicon\eBay.ico
c:\users\Hendrik\AppData\Roaming\Desktopicon\uninst.exe
.
((((((((((((((((((((((( Dateien erstellt von 2010-05-14 bis 2010-06-14 ))))))))))))))))))))))))))))))
.
2010-06-14 12:51 . 2010-06-14 12:51 -------- d-----w- c:\users\Gast\AppData\Local\temp
2010-06-14 12:51 . 2010-06-14 12:51 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-06-13 11:13 . 2010-06-13 11:13 -------- d-----w- c:\program files\Microsoft Silverlight
2010-06-12 22:55 . 2010-06-12 22:55 71992 ----a-w- c:\programdata\Apple Computer\Installer Cache\Safari 5.33.16.0\SetupAdmin.exe
2010-06-10 14:58 . 2010-06-10 14:58 -------- d-----w- c:\users\Hendrik\AppData\Roaming\Malwarebytes
2010-06-10 14:58 . 2010-04-29 10:19 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-10 14:58 . 2010-06-10 14:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-10 14:58 . 2010-06-10 14:58 -------- d-----w- c:\programdata\Malwarebytes
2010-06-10 14:58 . 2010-04-29 10:19 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-06-10 14:37 . 2010-06-10 14:37 -------- d-----w- c:\program files\CCleaner
2010-06-09 15:57 . 2010-04-05 17:01 67072 ----a-w- c:\windows\system32\asycfilt.dll
2010-06-09 15:54 . 2010-05-26 17:06 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-06-09 15:54 . 2010-05-26 14:47 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-06-09 15:42 . 2010-05-01 14:13 2037248 ----a-w- c:\windows\system32\win32k.sys
2010-05-26 10:32 . 2010-04-23 14:13 2048 ----a-w- c:\windows\system32\tzres.dll
2010-05-23 13:37 . 2010-05-23 13:37 -------- d-----r- C:\Sandbox
2010-05-23 13:36 . 2010-05-23 13:36 -------- d-----w- c:\program files\Sandboxie
2010-05-21 15:11 . 2010-05-21 15:11 -------- d-----w- c:\users\Hendrik\AppData\Roaming\LolClient
2010-05-21 14:43 . 2010-05-21 14:44 38784 ----a-w- c:\users\Hendrik\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-05-21 14:43 . 2010-05-21 14:44 38784 ----a-w- c:\users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-05-21 14:43 . 2010-05-21 14:44 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-05-21 13:30 . 2010-05-21 14:00 -------- d-----w- c:\users\Hendrik\AppData\Local\PMB Files
2010-05-21 13:30 . 2010-05-21 13:30 -------- d-----w- c:\programdata\PMB Files
2010-05-21 13:30 . 2010-05-21 13:30 -------- d-----w- c:\program files\Pando Networks
2010-05-18 14:23 . 2010-05-18 14:24 -------- d-----w- C:\devkitPro
2010-05-18 13:25 . 2010-04-12 15:29 411368 ----a-w- c:\windows\system32\deployJava1.dll
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-14 12:50 . 2009-03-31 12:55 -------- d-----w- c:\users\Hendrik\AppData\Roaming\Skype
2010-06-14 12:07 . 2009-03-31 16:23 -------- d-----w- c:\users\Hendrik\AppData\Roaming\ICQ
2010-06-14 12:06 . 2009-05-14 14:26 -------- d-----w- c:\users\Hendrik\AppData\Roaming\skypePM
2010-06-14 12:00 . 2008-04-16 11:11 618442 ----a-w- c:\windows\system32\perfh007.dat
2010-06-14 12:00 . 2008-04-16 11:11 122842 ----a-w- c:\windows\system32\perfc007.dat
2010-06-13 20:44 . 2008-12-05 18:55 12 ----a-w- c:\windows\bthservsdp.dat
2010-06-13 11:12 . 2009-10-04 10:13 -------- d-----w- c:\program files\Microsoft
2010-06-13 11:06 . 2008-12-05 21:29 45056 ----a-w- c:\windows\system32\acovcnt.exe
2010-06-12 23:00 . 2010-02-02 14:31 -------- d-----w- c:\program files\Safari
2010-06-12 08:35 . 2009-04-14 17:37 7592 ----a-w- c:\users\Hendrik\AppData\Local\d3d9caps.dat
2010-06-10 15:06 . 2010-01-17 00:21 -------- d-----w- c:\program files\Rightdown Software SearchBar
2010-06-10 13:14 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-06-10 10:45 . 2008-12-05 19:03 -------- d-----w- c:\programdata\Microsoft Help
2010-06-09 19:32 . 2010-02-16 16:51 -------- d-----w- c:\program files\ICQ7.0
2010-06-06 11:19 . 2010-05-14 14:03 -------- d-----w- c:\users\Hendrik\AppData\Roaming\Xfire
2010-06-03 23:43 . 2009-11-19 20:19 -------- d-----w- c:\users\Hendrik\AppData\Roaming\vlc
2010-05-30 18:38 . 2010-04-30 15:12 -------- d-----w- c:\users\Hendrik\AppData\Roaming\Audacity
2010-05-24 14:47 . 2009-03-31 12:19 124547 ----a-w- c:\programdata\nvModes.dat
2010-05-18 13:25 . 2009-04-20 18:44 -------- d-----w- c:\program files\Java
2010-05-14 14:07 . 2010-05-14 13:42 -------- d-----w- c:\program files\THQ
2010-05-14 14:06 . 2008-12-05 19:17 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-05-14 14:03 . 2010-05-14 14:03 -------- d-s---w- c:\program files\Xfire
2010-05-14 13:49 . 2010-05-14 13:49 8192 ----a-r- c:\users\Hendrik\AppData\Roaming\Microsoft\Installer\{D0B36BAF-3E9D-423E-8821-ED238C18DB0A}\IconD0B36BAF3.exe
2010-05-14 13:49 . 2010-05-14 13:49 6144 ----a-r- c:\users\Hendrik\AppData\Roaming\Microsoft\Installer\{D0B36BAF-3E9D-423E-8821-ED238C18DB0A}\Icon83F12F734.exe
2010-05-14 13:49 . 2010-05-14 13:49 11264 ----a-r- c:\users\Hendrik\AppData\Roaming\Microsoft\Installer\{D0B36BAF-3E9D-423E-8821-ED238C18DB0A}\Icon8F99E711.exe
2010-05-10 20:38 . 2009-09-29 18:25 -------- d-----w- c:\program files\Opera
2010-05-07 23:23 . 2010-05-07 21:04 -------- d-----w- c:\program files\mektek.net
2010-05-07 21:04 . 2010-05-07 21:04 26582 ----a-r- c:\users\Hendrik\AppData\Roaming\Microsoft\Installer\{6583D00E-0924-4950-8BE9-5D09FE70B333}\_A56E24F757E8A738F8C492.exe
2010-05-07 21:04 . 2010-05-07 21:04 26582 ----a-r- c:\users\Hendrik\AppData\Roaming\Microsoft\Installer\{6583D00E-0924-4950-8BE9-5D09FE70B333}\_17A37D12E91C20333FE6AE.exe
2010-05-04 15:25 . 2010-05-04 15:18 -------- d-----w- c:\users\Hendrik\AppData\Roaming\Guitar Pro 6
2010-05-04 15:18 . 2010-05-04 15:18 -------- d-----w- c:\programdata\Guitar Pro 6
2010-05-04 05:59 . 2010-06-09 15:47 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 05:55 . 2010-06-09 15:47 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-05-04 05:55 . 2010-06-09 15:47 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-05-04 04:31 . 2010-06-09 15:47 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-05-01 20:43 . 2010-05-01 20:42 -------- d-----w- c:\program files\iTunes
2010-05-01 20:43 . 2010-05-01 20:43 -------- d-----w- c:\program files\iPod
2010-05-01 20:43 . 2009-12-17 19:49 -------- d-----w- c:\program files\Common Files\Apple
2010-05-01 20:38 . 2010-05-01 20:38 -------- d-----w- c:\program files\Bonjour
2010-05-01 20:36 . 2010-05-01 20:36 73000 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe
2010-05-01 20:34 . 2010-05-01 20:34 -------- d-----w- c:\programdata\WindowsSearch
2010-05-01 12:58 . 2009-04-23 19:32 -------- d-----w- c:\users\Hendrik\AppData\Roaming\gtk-2.0
2010-04-30 15:12 . 2010-04-30 15:12 -------- d-----w- c:\program files\Conduit
2010-04-30 15:12 . 2010-04-30 15:12 -------- d-----w- c:\program files\Softonic_Deutsch
2010-04-30 15:12 . 2010-04-30 15:11 -------- d-----w- c:\program files\Audacity 1.3 Beta (Unicode)
2010-04-30 13:57 . 2010-04-15 15:52 -------- d-----w- c:\program files\Paint.NET
2010-04-22 19:16 . 2010-04-22 19:16 -------- d-----w- c:\program files\WiFiConnector
2010-04-20 11:48 . 2010-04-20 11:48 -------- d-----w- c:\program files\Common Files\Skype
2010-04-18 20:35 . 2010-04-18 20:35 -------- d-----w- c:\program files\AutoIt3
2010-04-18 20:32 . 2009-03-31 12:17 -------- d-----w- c:\program files\Common Files\Adobe
2010-04-15 16:14 . 2010-04-15 15:57 89280248 ----a-w- c:\users\Hendrik\AppData\Roaming\Samsung\New PC Studio\LiveUpdate\Setup_For_Full_Update_IH2_7.exe
2010-04-08 11:20 . 2010-04-08 11:20 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-04-08 11:20 . 2010-04-08 11:20 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-03-27 23:15 . 2010-03-27 23:15 79144 ----a-w- c:\programdata\Apple Computer\Installer Cache\Safari 5.31.22.7\SetupAdmin.exe
2010-03-24 20:40 . 2009-03-31 12:13 107024 ----a-w- c:\users\Hendrik\AppData\Local\GDIPFONTCACHEV1.DAT
2010-03-24 19:55 . 2009-04-05 09:57 107024 ----a-w- c:\users\Gast\AppData\Local\GDIPFONTCACHEV1.DAT
2010-03-19 12:25 . 2009-04-25 10:05 977816 begin_of_the_skype_highlighting**************05 977816******end_of_the_skype_highlighting begin_of_the_skype_highlighting**************05 977816******end_of_the_skype_highlighting begin_of_the_skype_highlighting**************05 977816******end_of_the_skype_highlighting begin_of_the_skype_highlighting**************05 977816******end_of_the_skype_highlighting begin_of_the_skype_highlighting**************05 977816******end_of_the_skype_highlighting begin_of_the_skype_highlighting**************05 977816******end_of_the_skype_highlighting begin_of_the_skype_highlighting**************05 977816******end_of_the_skype_highlighting begin_of_the_skype_highlighting**************05 977816******end_of_the_skype_highlighting begin_of_the_skype_highlighting**************05 977816******end_of_the_skype_highlighting begin_of_the_skype_highlighting**************05 977816******end_of_the_skype_highlighting begin_of_the_skype_highlighting**************05 977816******end_of_the_skype_highlighting ----a-w- c:\program files\HyCam2.exe
2010-03-17 20:39 . 2010-03-17 20:39 509552 ----a-w- c:\programdata\Google\Google Toolbar\Update\gtbFF1E.tmp.exe
2010-03-15 12:45 . 2009-04-25 10:05 5784 ----a-w- c:\program files\HyCam2.tlb
2010-03-12 11:55 . 2009-04-25 10:05 115216 ----a-w- c:\program files\HyCam2.chm
2010-03-12 10:50 . 2009-04-25 10:05 173992 ----a-w- c:\program files\UnHyCam2.exe
2010-03-11 18:16 . 2009-04-25 10:05 132608 ----a-w- c:\program files\CamRes2.dll
2009-12-31 16:03 . 2009-04-25 10:05 44032 ----a-w- c:\program files\MClick2.dll
2008-07-02 03:28 . 2008-07-02 03:28 61440 ----a-w- c:\program files\Common Files\CPInstallAction.dll
2008-05-23 10:08 . 2009-04-25 10:05 3271 ----a-w- c:\program files\agreement.txt
2008-05-22 17:35 . 2008-05-22 17:35 51962 ----a-w- c:\program files\Common Files\banner.jpg
2007-06-12 18:34 . 2007-06-12 18:34 35822 ----a-w- c:\program files\Common Files\ASPG_icon.ico
2006-07-09 04:13 . 2009-04-25 10:05 82 ----a-w- c:\program files\HomePage.url
2004-05-05 11:57 . 2009-04-25 10:05 2018 ----a-w- c:\program files\readme.txt
2004-04-22 10:00 . 2009-04-25 10:05 626 ----a-w- c:\program files\HyCam2.exe.manifest
1999-06-24 10:49 . 2009-04-25 10:05 421 ----a-w- c:\program files\8-44100u.wav
1999-06-24 10:49 . 2009-04-25 10:05 587 ----a-w- c:\program files\8-44100d.wav
1999-06-24 10:47 . 2009-04-25 10:05 225 ----a-w- c:\program files\8-22050u.wav
1999-06-24 10:47 . 2009-04-25 10:05 317 ----a-w- c:\program files\8-22050d.wav
1999-06-24 10:46 . 2009-04-25 10:05 135 ----a-w- c:\program files\8-11025u.wav
1999-06-24 10:46 . 2009-04-25 10:05 183 ----a-w- c:\program files\8-11025d.wav
1999-06-24 10:44 . 2009-04-25 10:05 127 ----a-w- c:\program files\8-8000u.wav
1999-06-24 10:43 . 2009-04-25 10:05 151 ----a-w- c:\program files\8-8000d.wav
1999-06-24 10:41 . 2009-04-25 10:05 220 ----a-w- c:\program files\16-8000u.wav
1999-06-24 10:40 . 2009-04-25 10:05 260 ----a-w- c:\program files\16-8000d.wav
1999-06-24 10:38 . 2009-04-25 10:05 956 ----a-w- c:\program files\16-44100u.wav
1999-06-24 10:37 . 2009-04-25 10:05 1186 ----a-w- c:\program files\16-44100d.wav
1999-06-24 10:34 . 2009-04-25 10:05 442 ----a-w- c:\program files\16-22050u.wav
1999-06-24 10:34 . 2009-04-25 10:05 652 ----a-w- c:\program files\16-22050d.wav
1999-06-24 09:54 . 2009-04-25 10:05 340 ----a-w- c:\program files\16-11025d.wav
1999-06-24 09:50 . 2009-04-25 10:05 326 ----a-w- c:\program files\16-11025u.wav
2009-03-31 20:47 . 2009-03-31 19:28 324976 ----a-w- c:\program files\mozilla firefox\components\coFFPlgn.dll
2009-11-05 14:16 . 2009-03-31 16:07 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{8dbb6d8e-e4a6-4e3b-9753-af78b226441c}"= "c:\program files\Softonic_Deutsch\tbSoft.dll" [2009-12-31 2349080]
[HKEY_CLASSES_ROOT\clsid\{8dbb6d8e-e4a6-4e3b-9753-af78b226441c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8dbb6d8e-e4a6-4e3b-9753-af78b226441c}]
2009-12-31 09:53 2349080 ----a-w- c:\program files\Softonic_Deutsch\tbSoft.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{081230F8-EA50-42A9-983C-D22ABC2EED3B}"= "c:\program files\FreeRIP3\Toolband.dll" [2009-10-16 282624]
"{8dbb6d8e-e4a6-4e3b-9753-af78b226441c}"= "c:\program files\Softonic_Deutsch\tbSoft.dll" [2009-12-31 2349080]
[HKEY_CLASSES_ROOT\clsid\{081230f8-ea50-42a9-983c-d22abc2eed3b}]
[HKEY_CLASSES_ROOT\ToolBand.ToolBandObj.1]
[HKEY_CLASSES_ROOT\TypeLib\{0097E905-1DFB-4A9C-9871-A4F95FD58945}]
[HKEY_CLASSES_ROOT\ToolBand.ToolBandObj]
[HKEY_CLASSES_ROOT\clsid\{8dbb6d8e-e4a6-4e3b-9753-af78b226441c}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{081230F8-EA50-42A9-983C-D22ABC2EED3B}"= "c:\program files\FreeRIP3\Toolband.dll" [2009-10-16 282624]
[HKEY_CLASSES_ROOT\clsid\{081230f8-ea50-42a9-983c-d22abc2eed3b}]
[HKEY_CLASSES_ROOT\ToolBand.ToolBandObj.1]
[HKEY_CLASSES_ROOT\TypeLib\{0097E905-1DFB-4A9C-9871-A4F95FD58945}]
[HKEY_CLASSES_ROOT\ToolBand.ToolBandObj]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-05 39408]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883840]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-05-13 26192168]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"AutoStartNPSAgent"="c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe" [2009-04-02 102400]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2010-02-03 394984]
"ICQ"="c:\program files\ICQ7.0\ICQ.exe" [2010-06-08 133368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"CLMLServer"="c:\program files\ASUS\AI TouchMedia\AI TouchMedia\Kernel\CLML\CLMLSvc.exe" [2008-06-12 196608]
"P2Go_Menu"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"PCMAgent"="c:\program files\ASUS\AI TouchMedia\AI TouchMedia\PCMAgent.exe" [2008-06-12 212992]
"PlayMovie"="c:\program files\ASUS\AI TouchMedia\PlayMovie\PMVService.exe" [2008-05-20 172032]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-11-05 30192]
"HControlUser"="c:\program files\ASUS\ATK Hotkey\HControlUser.exe" [2008-01-12 98304]
"ATKOSD2"="c:\program files\ASUS\ATKOSD2\ATKOSD2.exe" [2008-07-15 7651328]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-06-25 13543968]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-06-25 92704]
"RtHDVCpl"="RtHDVCpl.exe" [2008-06-13 6183456]
"ATKMEDIA"="c:\program files\ASUS\ATK Media\DMedia.exe" [2008-06-25 159744]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-07-03 1328424]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2007-10-11 29984]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2007-10-11 46368]
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-08-31 328992]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2008-02-19 1089536]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2007-12-21 86016]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"Ulead Memory Card Detector"="c:\program files\Ulead Systems\Ulead Photo Explorer 7.0\Monitor.exe" [2002-09-12 40960]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"Skytel"="Skytel.exe" [2007-11-20 1826816]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"ASUS Screen Saver Protector"="c:\windows\AsScrPro.exe" [2008-12-05 3054136]
"ASUS Camera ScreenSaver"="c:\windows\AsScrProlog.exe" [2008-12-05 47672]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2010-03-30 1820040]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-04-13 47392]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
c:\users\Hendrik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-4-16 384000]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-4-10 752168]
phase-6 Reminder.lnk - c:\program files\phase-6\phase-6\reminder\reminder.exe [2009-7-13 1032192]
Registrierungsprogramm ausfhren.lnk - c:\program files\WiFiConnector\NintendoWFCReg.exe [2010-4-22 1073152]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):79,2b,9c,45,85,67,ca,01
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-03-17 135664]
R3 AVerAF15;AVerMedia BDA Digital Tuner;c:\windows\system32\Drivers\AVerAF15.sys [2007-07-17 269056]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2008-01-29 29736]
R3 GoogleDesktopManager-093009-130223;Google Desktop Manager 5.9.909.30391;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2009-11-05 30192]
R3 PAC207;SoC PC-Camera;c:\windows\system32\DRIVERS\PFC027.SYS [2006-12-05 507136]
R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\DRIVERS\ss_bbus.sys [2009-03-20 90112]
R3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\DRIVERS\ss_bmdfl.sys [2009-03-20 14976]
R3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\DRIVERS\ss_bmdm.sys [2009-03-20 121856]
S0 lullaby;lullaby;c:\windows\system32\DRIVERS\lullaby.sys [2008-05-29 15416]
S2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\ASUS\AI TouchMedia\PlayMovie\000.fcl [2008-05-20 61424]
S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-06-10 108289]
S2 Apache2.2;Apache2.2;c:\xampp\apache\bin\httpd.exe [2009-08-05 24640]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2009-03-31 233472]
S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [2010-03-30 1107336]
S2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [2010-01-03 246520]
S2 PLCNDIS5;PLCNDIS5 NDIS Protocol Driver;c:\windows\system32\plcndis5.sys [2004-05-17 17280]
S3 DCamUSBET;USB2.0 1.3M UVC WebCam;c:\windows\system32\DRIVERS\etDevice.sys [2007-09-06 474624]
S3 FiltUSBET;ET USB Device Lower Filter;c:\windows\system32\DRIVERS\etFilter.sys [2008-02-05 206464]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2009-03-31 36608]
S3 itecir;ITECIR Infrared Receiver;c:\windows\system32\DRIVERS\itecir.sys [2007-12-19 54784]
S3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2009-05-28 4233728]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-06-25 43040]
S3 ScanUSBET;ET USB Still Image Capture Device;c:\windows\system32\DRIVERS\etScan.sys [2008-01-31 6528]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 18:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Inhalt des "geplante Tasks" Ordners
2010-06-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-17 20:57]
2010-06-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-17 20:57]
2010-06-14 c:\windows\Tasks\User_Feed_Synchronization-{DC9042BE-4D87-4D79-99A4-F19A2CC94F8E}.job
- c:\windows\system32\msfeedssync.exe [2010-06-09 04:30]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT1351351
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=ASUS&bmod=ASUS
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: &FreeRIP Search - c:\program files\FreeRIP3\Toolband.dll/MENUSEARCH.HTM
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
FF - ProfilePath - c:\users\Hendrik\AppData\Roaming\Mozilla\Firefox\Profiles\6fbedacu.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1351351&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://ogame.de/|hxxp://www.homebrewwelt.com/|hxxp://board.nostale.de/|hxxp://de.ikariam.com/|hxxp://de.mmogame.com/
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1351351&q=
FF - component: c:\program files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\components\SEPsearchhelperff.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
FF - component: c:\users\Hendrik\AppData\Roaming\Mozilla\Firefox\Profiles\6fbedacu.default\extensions\{8dbb6d8e-e4a6-4e3b-9753-af78b226441c}\components\FFExternalAlert.dll
FF - component: c:\users\Hendrik\AppData\Roaming\Mozilla\Firefox\Profiles\6fbedacu.default\extensions\{8dbb6d8e-e4a6-4e3b-9753-af78b226441c}\components\RadioWMPCore.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: c:\program files\Picasa2\npPicasa2.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\Hendrik\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: c:\users\Hendrik\AppData\Roaming\Mozilla\Firefox\Profiles\6fbedacu.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071303000004.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX Richtlinien ----
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
AddRemove-eBay Icon - c:\users\Hendrik\AppData\Roaming\Desktopicon\uninst.exe
AddRemove-TeamSpeak 3 Client - h:\liberkey\MyApps\TeamSpeak\uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2010-06-14 14:51
Windows 6.0.6002 Service Pack 2 NTFS
Scanne versteckte Prozesse...
Scanne versteckte Autostarteinträge...
Scanne versteckte Dateien...
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
"ImagePath"="\??\c:\program files\ASUS\AI TouchMedia\PlayMovie\000.fcl"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
[HKEY_USERS\S-1-5-21-1470412310-2290689196-1735228460-1000\Software\SecuROM\License information*]
"datasecu"=hex:62,df,fe,c0,aa,11,50,bd,b4,2b,29,02,13,41,bb,f8,b3,86,d9,01,89,
59,26,aa,85,08,bc,05,33,ca,51,f5,1e,f0,26,f1,46,03,42,9e,5a,c1,12,a8,71,70,\
"rkeysecu"=hex:2e,8d,de,ce,c6,38,c5,a5,de,58,6b,db,03,d5,6e,a8
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:00000000
.
Zeit der Fertigstellung: 2010-06-14 14:59:05
ComboFix-quarantined-files.txt 2010-06-14 12:58
Vor Suchlauf: 12 Verzeichnis(se), 65'203'277'824 Bytes frei
Nach Suchlauf: 17 Verzeichnis(se), 65'566'289'920 Bytes frei
- - End Of File - - 73A17D21214721073EBC54C51D47908F --- --- --- |