Code:
ComboFix 10-12-14.07 - Andreas L 15.12.2010 17:24:06.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.3070.1692 [GMT 1:00]
ausgeführt von:: d:\users\Andreas L\Desktop\cofi.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
d:\windows\Install
d:\windows\system32\config.dat
.
((((((((((((((((((((((( Dateien erstellt von 2010-11-15 bis 2010-12-15 ))))))))))))))))))))))))))))))
.
2010-12-15 16:30 . 2010-12-15 16:30 -------- d-----w- d:\users\Andreas L\AppData\Local\temp
2010-12-15 16:30 . 2010-12-15 16:30 -------- d-----w- d:\users\Default\AppData\Local\temp
2010-12-14 20:08 . 2010-08-26 04:23 13312 ----a-w- d:\program files\Internet Explorer\iecompat.dll
2010-12-14 20:04 . 2010-08-26 16:34 1696256 ----a-w- d:\windows\system32\gameux.dll
2010-12-14 20:04 . 2010-08-26 16:33 28672 ----a-w- d:\windows\system32\Apphlpdm.dll
2010-12-14 20:04 . 2010-08-26 14:23 4240384 ----a-w- d:\windows\system32\GameUXLegacyGDFs.dll
2010-12-14 18:36 . 2010-12-14 18:36 -------- d-----w- D:\_OTL
2010-12-14 14:08 . 2010-12-14 14:08 4096 ----a-w- d:\windows\system32\096E1.tmp
2010-12-13 22:32 . 2010-12-13 22:33 -------- d-----w- d:\program files\ERUNT
2010-12-13 22:25 . 2010-12-13 22:25 -------- d-----w- d:\users\Andreas L\AppData\Roaming\Malwarebytes
2010-12-13 22:25 . 2010-12-13 22:25 -------- d-----w- d:\programdata\Malwarebytes
2010-12-13 22:25 . 2010-11-29 16:42 38224 ----a-w- d:\windows\system32\drivers\mbamswissarmy.sys
2010-12-13 22:25 . 2010-12-13 22:25 -------- d-----w- d:\program files\Malwarebytes' Anti-Malware
2010-12-13 22:25 . 2010-11-29 16:42 20952 ----a-w- d:\windows\system32\drivers\mbam.sys
2010-12-13 21:15 . 2010-12-13 22:42 -------- d-----w- d:\windows\system32\System
2010-12-10 17:11 . 2010-12-10 17:12 158382 ---h--w- d:\users\Andreas L\AppData\Roaming\Andreas L1.dll
2010-12-09 09:46 . 1998-06-17 17:07 57344 ----a-w- d:\windows\system32\Mfc42loc.dll
2010-12-09 09:43 . 2010-12-09 09:44 -------- d-----w- d:\program files\EA GAMES
2010-12-09 01:08 . 2010-12-09 01:08 -------- d-----w- d:\program files\LogMeIn Hamachi
2010-12-08 23:35 . 2010-12-15 16:30 -------- d-----w- d:\users\Andreas L\AppData\Local\LogMeIn Hamachi
2010-12-08 23:32 . 2009-03-18 15:35 26176 ---ha-w- d:\windows\system32\hamachi.sys
2010-12-08 22:16 . 2010-12-08 22:16 -------- d-----w- d:\program files\Alcohol Soft
2010-12-03 06:26 . 2010-12-03 06:26 -------- d-----w- d:\users\Andreas L\AppData\Local\Activision
2010-12-01 22:48 . 2010-12-01 22:48 -------- d-----w- d:\program files\ConduitEngine
2010-11-28 14:10 . 2010-11-28 14:10 -------- d-----w- d:\users\Andreas L\AppData\Roaming\Flatcast
2010-11-28 14:10 . 2010-11-28 14:10 695578 ----a-w- d:\windows\unins000.exe
2010-11-28 04:31 . 2010-11-28 04:31 -------- d-----w- d:\program files\Rockstar Games
2010-11-27 22:53 . 2010-12-13 22:42 -------- d-----w- D:\INSTALL
2010-11-26 08:37 . 2010-11-26 08:37 -------- d-----w- d:\programdata\Nexon
2010-11-26 01:24 . 2010-12-05 00:11 -------- d-----w- D:\Nexon
2010-11-26 01:24 . 2010-12-05 00:11 235 ----a-w- d:\windows\system32\nxEuUninstall.bat
2010-11-26 01:24 . 2010-12-05 00:11 446464 ----a-w- d:\windows\NEXON_EU_DownloaderUpdater.exe
2010-11-23 08:51 . 2010-11-10 04:33 6273872 ----a-w- d:\programdata\Microsoft\Windows Defender\Definition Updates\{C63BC180-2C48-40EC-A43C-21B37B479C48}\mpengine.dll
2010-11-20 02:52 . 2010-11-20 02:52 -------- d-----w- d:\users\Andreas L\AppData\Local\Yahoo!
2010-11-19 09:30 . 2010-11-19 09:30 -------- d-----w- d:\program files\SD EnterNET
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-12 01:52 . 2010-08-05 20:09 43520 ----a-w- d:\windows\system32\CmdLineExt03.dll
2010-12-10 09:17 . 2010-08-07 00:40 139128 ----a-w- d:\windows\system32\drivers\PnkBstrK.sys
2010-12-10 09:17 . 2010-08-07 20:20 215128 ----a-w- d:\windows\system32\PnkBstrB.xtr
2010-12-10 09:17 . 2010-08-07 00:40 215128 ----a-w- d:\windows\system32\PnkBstrB.exe
2010-12-09 14:40 . 2010-08-07 00:40 75136 ----a-w- d:\windows\system32\PnkBstrA.exe
2010-12-09 14:40 . 2010-08-07 00:40 270904 ----a-w- d:\windows\system32\PnkBstrB.ex0
2010-11-25 07:43 . 2010-08-07 00:40 138056 ----a-w- d:\users\Andreas L\AppData\Roaming\PnkBstrK.sys
2010-11-10 22:19 . 2010-11-10 22:19 472808 ----a-w- d:\windows\system32\deployJava1.dll
2010-10-24 10:06 . 2010-10-24 10:06 281760 ----a-w- d:\windows\system32\drivers\atksgt.sys
2010-10-24 10:06 . 2010-10-24 10:06 25888 ----a-w- d:\windows\system32\drivers\lirsgt.sys
2010-10-19 09:41 . 2010-08-04 15:27 222080 ------w- d:\windows\system32\MpSigStub.exe
2010-10-13 20:30 . 2010-10-13 20:30 107888 ----a-w- d:\windows\system32\CmdLineExt.dll
2010-09-27 07:07 . 2010-09-27 07:07 113216 ----a-w- d:\programdata\Microsoft\VCExpress\9.0\1031\ResourceCache.dll
2010-09-27 07:07 . 2010-09-27 07:07 416 ----a-w- d:\programdata\Microsoft\MSDN\9.0\1031\ResourceCache.dll
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}"= "d:\program files\softonic-de3\tbsof2.dll" [2010-10-18 3908192]
[HKEY_CLASSES_ROOT\clsid\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-10-18 10:26 3908192 ----a-w- d:\program files\ConduitEngine\ConduitEngine.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}]
2010-10-18 10:26 3908192 ----a-w- d:\program files\softonic-de3\tbsof2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}"= "d:\program files\softonic-de3\tbsof2.dll" [2010-10-18 3908192]
[HKEY_CLASSES_ROOT\clsid\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065}"= "d:\program files\softonic-de3\tbsof2.dll" [2010-10-18 3908192]
[HKEY_CLASSES_ROOT\clsid\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="d:\program files\Windows Sidebar\sidebar.exe" [2009-04-10 1233920]
"msnmsgr"="d:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="d:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"RtHDVCpl"="d:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2008-12-26 6707744]
"AVMWlanClient"="d:\program files\avmwlanstick\FRITZWLANMini.exe" [2007-02-02 283136]
"Monitor"="d:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2010-07-12 74752]
"QuickTime Task"="d:\program files\QuickTime\QTTask.exe" [2010-08-10 421888]
"VirtualCloneDrive"="d:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-06-17 85160]
"trustGTX14"="d:\program files\Trust\GXT14 Mouse\POINTERGHOST.exe" [2009-06-05 4833792]
"ArcSoft Connection Service"="d:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2007-10-11 31232]
"Adobe Reader Speed Launcher"="d:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="d:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"SunJavaUpdateSched"="d:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"LogMeIn Hamachi Ui"="d:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2010-12-06 1910152]
d:\users\Andreas L\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
IMVU.lnk - d:\users\Andreas L\AppData\Roaming\IMVUClient\IMVUQualityAgent.exe [2010-12-1 21760]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKLM\~\startupfolder\D:^Users^Andreas L^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^IMVU.lnk]
path=d:\users\Andreas L\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\IMVU.lnk
backup=d:\windows\pss\IMVU.lnk.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\D:^Users^Andreas L^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk]
path=d:\users\Andreas L\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
backup=d:\windows\pss\OpenOffice.org 3.2.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
2010-12-06 07:31 1910152 ----a-w- d:\program files\LogMeIn Hamachi\hamachi-2-ui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2010-11-11 01:07 1242448 ----a-w- d:\program files\Steam\Steam.exe
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;d:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 avmeject;AVM Eject;d:\windows\system32\drivers\avmeject.sys [2007-01-25 4352]
R3 CoachVid;CoachVid;d:\windows\system32\DRIVERS\CoachVid.sys [2007-04-20 45344]
R3 KMWDFilterV1;KMWDFilterV1;d:\windows\System32\Drivers\RPGMOUSEV1.sys [2009-06-10 18432]
R3 npggsvc;nProtect GameGuard Service;d:\windows\system32\GameMon.des [2010-09-06 3648584]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;d:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 sptd;sptd;d:\windows\System32\Drivers\sptd.sys [2010-08-10 691696]
S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;d:\program files\LogMeIn Hamachi\hamachi-2.exe [2010-12-06 1238408]
S2 TeamViewer5;TeamViewer 5;d:\program files\TeamViewer\Version5\TeamViewer_Service.exe [2010-07-06 173352]
S3 FWLANUSB;AVM FRITZ!WLAN;d:\windows\system32\DRIVERS\fwlanusb.sys [2007-01-25 265088]
S3 PAC207;Trust WB-1400T Webcam;d:\windows\system32\DRIVERS\PFC027.SYS [2006-11-20 506112]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ghpyg
[HKEY_CURRENT_USER\software\microsoft\active setup\installed components\{AD57F3D9-974E-EDD9-D5AE-74BA752AB2BA}]
d:\users\ANDREA~1\AppData\Local\Temp\taxi_tool.exe [BU]
[HKEY_CURRENT_USER\software\microsoft\active setup\installed components\{BCDACEDA-CAD5-3B51-DB84-64BA7783E1A0}]
d:\users\Andreas L\AppData\Roaming\javasvr.exe [BU]
.
.
------- Zusätzlicher Suchlauf -------
.
uInternet Settings,ProxyOverride = fritz.box;192.168.178.1
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - d:\users\Andreas L\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IMVU\Run IMVU.lnk
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
HKLM-Explorer_Run-javasvr.exe - d:\users\Andreas L\AppData\Roaming\javasvr.exe
MSConfigStartUp-BitTorrent - d:\program files\BitTorrent\BitTorrent.exe
ActiveSetup-{AD57F3D9-974E-EDD9-D5AE-74BA752AB2BA} - d:\users\ANDREA~1\AppData\Local\Temp\taxi_tool.exe
ActiveSetup-{BCDACEDA-CAD5-3B51-DB84-64BA7783E1A0} - d:\users\Andreas L\AppData\Roaming\javasvr.exe
AddRemove-DesertCombat - d:\windows\iun6002.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2010-12-15 17:30
Windows 6.0.6002 Service Pack 2 NTFS
Scanne versteckte Prozesse...
Scanne versteckte Autostarteinträge...
Scanne versteckte Dateien...
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\npggsvc]
"ImagePath"="d:\windows\system32\GameMon.des -service"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
[HKEY_USERS\S-1-5-21-1744265244-841379661-1100195608-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:a1,c5,c2,d6,a2,f6,01,66,df,16,32,48,d5,a4,91,b1,1d,5c,78,61,e4,84,63,
12,e2,6c,26,07,41,a9,65,2e,1d,91,c4,7f,7f,27,fc,a2,93,9d,ef,84,b0,be,3a,86,\
"??"=hex:cf,04,6d,49,dd,57,37,e3,6a,e6,2e,52,5d,86,22,38
[HKEY_USERS\S-1-5-21-1744265244-841379661-1100195608-1000\Software\SecuROM\License information*]
"datasecu"=hex:c5,fd,eb,f7,b2,79,20,59,f4,c3,12,25,21,57,84,b6,0e,9c,50,57,53,
76,39,fd,c9,1f,b5,7a,94,fc,1b,4b,61,83,eb,79,06,fb,35,40,50,0c,13,81,45,61,\
"rkeysecu"=hex:1a,37,50,eb,da,7b,3d,34,06,1d,23,61,20,2d,1f,2d
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@d:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="d:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Zeit der Fertigstellung: 2010-12-15 17:33:26
ComboFix-quarantined-files.txt 2010-12-15 16:33
Vor Suchlauf: 14 Verzeichnis(se), 128.056.766.464 Bytes frei
Nach Suchlauf: 16 Verzeichnis(se), 128.442.806.272 Bytes frei
- - End Of File - - 1C4414E36CAD4224D25AAF9CD579A14B Zitat:
welche programme soll ich benutzen um meinen rechner bestmöglich sauber zu halten? welche maßnamen? welchen antiviren scanner wäre am besten?
| mfg Laudi |