Code:
ComboFix 11-05-30.08 - aljosa 05/31/2011 17:10:32.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1031.18.2046.1418 [GMT 2:00]
ausgeführt von:: c:\dokumente und einstellungen\aljosa\Desktop\cofi.exe
AV: McAfee Anti-Virus und Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Firewall *Disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\cannonhill\cannonhill.exe
c:\dokumente und einstellungen\aljosa\DrvMgt.dll
c:\dokumente und einstellungen\aljosa\setx.exe
c:\dokumente und einstellungen\aljosa\WINDOWS
C:\test.txt
c:\windows\daemon.dll
c:\windows\system32\drivers\1028_DELL_XPS_Dell DXP051 .MRK
c:\windows\system32\drivers\DELL_XPS_Dell DXP051 .MRK
c:\windows\system32\logs
.
.
((((((((((((((((((((((((((((((((((((((( Treiber/Dienste )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_P4P_SERVICE
.
.
((((((((((((((((((((((( Dateien erstellt von 2011-04-28 bis 2011-05-31 ))))))))))))))))))))))))))))))
.
.
2011-05-30 17:35 . 2011-05-30 17:35 -------- d-----w- C:\_OTL
2011-05-30 12:51 . 2011-05-30 12:55 -------- d-----w- c:\programme\ICQ7.5
2011-05-30 00:32 . 2010-12-20 16:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-30 00:32 . 2010-12-20 16:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-05-30 00:32 . 2011-05-30 00:32 -------- d-----w- C:\Malwarebytes' Anti-Malware
2011-05-29 10:47 . 2011-05-31 15:26 -------- d-----w- c:\dokumente und einstellungen\aljosa\Anwendungsdaten\go
2011-05-29 10:47 . 2011-05-31 14:16 -------- d-----w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\Easybits GO
2011-05-19 10:49 . 2011-05-19 10:49 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-14 12:01 . 2010-08-13 10:30 9344 ----a-w- c:\windows\system32\drivers\mfeclnk.sys
2011-04-14 12:01 . 2010-08-13 10:29 88736 ----a-w- c:\windows\system32\drivers\mfendisk.sys
2011-04-14 12:01 . 2010-08-13 10:29 84488 ----a-w- c:\windows\system32\drivers\mferkdet.sys
2011-04-14 12:01 . 2010-08-13 10:29 84200 ----a-w- c:\windows\system32\drivers\mfetdi2k.sys
2011-04-14 12:01 . 2010-08-13 10:29 387480 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2011-04-14 12:01 . 2010-08-13 10:29 314088 ----a-w- c:\windows\system32\drivers\mfefirek.sys
2011-04-14 12:01 . 2010-08-13 10:29 95824 ----a-w- c:\windows\system32\drivers\mfeapfk.sys
2011-04-14 12:01 . 2010-08-13 10:29 56064 ----a-w- c:\windows\system32\drivers\cfwids.sys
2011-04-14 12:01 . 2010-08-13 10:29 52320 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2011-04-14 12:01 . 2010-08-13 10:29 153280 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2011-04-06 14:20 . 2011-04-06 14:20 91424 ----a-w- c:\windows\system32\dnssd.dll
2011-04-06 14:20 . 2011-04-06 14:20 107808 ----a-w- c:\windows\system32\dns-sd.exe
2011-04-03 20:48 . 2011-04-03 20:48 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-04-03 20:48 . 2007-05-01 09:54 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-03-07 05:33 . 2005-08-19 23:55 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:36 . 2005-08-19 23:34 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:53 . 2005-08-19 23:34 1858048 ----a-w- c:\windows\system32\win32k.sys
2011-04-29 19:46 . 2011-03-22 18:09 142296 ----a-w- c:\programme\mozilla firefox\components\browsercomps.dll
2011-04-14 12:01 . 2010-08-13 10:30 24376 ----a-w- c:\programme\mozilla firefox\components\Scriptff.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\programme\Skype\Phone\Skype.exe" [2011-01-26 15026056]
"ICQ"="c:\programme\ICQ7.5\ICQ.exe" [2011-05-30 124216]
"WMPNSCFG"="c:\programme\Windows Media Player\WMPNSCFG.exe" [2006-11-03 204288]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2006-02-10 282624]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-05-20 28160]
"DIGServices"="c:\programme\ESPNRunTime\DIGServices.exe" [2006-07-14 106496]
"DLCXCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [2006-06-07 106496]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-03-16 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-03-16 13670504]
"RemoteControl10"="c:\programme\CyberLink\PowerDVD10\PDVD10Serv.exe" [2010-02-02 87336]
"BDRegion"="c:\programme\Cyberlink\Shared files\brs.exe" [2010-03-13 75048]
"DivXUpdate"="c:\programme\DivX\DivX Update\DivXUpdate.exe" [2010-04-12 1135912]
"mcui_exe"="c:\programme\McAfee.com\Agent\mcagent.exe" [2011-04-05 1195408]
"QuickTime Task"="c:\programme\QuickTime\qttask.exe" [2010-11-29 421888]
"GrooveMonitor"="c:\programme\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"SunJavaUpdateSched"="c:\programme\Gemeinsame Dateien\Java\Java Update\jusched.exe" [2010-10-29 249064]
"iTunesHelper"="c:\programme\iTunes\iTunesHelper.exe" [2011-04-14 421160]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0c:\dokume~1\alluse~1\anwend~1\spywar~1\sp_rsdel.exe \??\c:\dokume~1\alluse~1\anwend~1\spywar~1\sp_rsdel.dat
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Adobe Reader - Schnellstart.lnk]
path=c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\Adobe Reader - Schnellstart.lnk
backup=c:\windows\pss\Adobe Reader - Schnellstart.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Dell Network Assistant.lnk]
path=c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\Dell Network Assistant.lnk
backup=c:\windows\pss\Dell Network Assistant.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Google Updater.lnk]
path=c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\Google Updater.lnk
backup=c:\windows\pss\Google Updater.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Logitech SetPoint.lnk]
path=c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\Logitech SetPoint.lnk
backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^VPro620.lnk]
path=c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\VPro620.lnk
backup=c:\windows\pss\VPro620.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
2007-06-21 12:42 70952 ----a-r- c:\programme\Gemeinsame Dateien\aol\ACS\AOLDial.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2007-09-20 14:35 202024 ----a-w- c:\programme\Gemeinsame Dateien\Nero\Lib\NMBgMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
2008-04-14 02:23 110592 ----a-w- c:\windows\system32\bthprops.cpl
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
2005-01-20 14:10 58992 ----a-w- c:\programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-10-30 11:57 369200 ----a-w- c:\programme\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DIGStream]
2006-02-10 12:06 278528 ----a-w- c:\programme\DIGStream\digstream.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dlcxmon.exe]
2006-06-14 12:51 286720 ----a-w- c:\programme\Dell Photo AIO Printer 926\dlcxmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher]
2005-10-05 02:12 94208 -c--a-w- c:\programme\Dell\Media Experience\DMXLauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core]
2006-08-16 11:33 1826816 -c--a-w- c:\programme\Electronic Arts\EA Downloader\Core.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ECenter]
2006-08-30 10:40 28672 ----a-w- c:\dell\E-Center\EULAl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
2005-09-29 13:01 67584 ----a-w- c:\windows\ehome\ehtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FaxCenterServer]
2006-06-15 10:03 307200 -c--a-w- c:\programme\Dell PC Fax\fm3032.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 09:44 31072 ----a-w- c:\programme\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
2006-11-13 11:50 1289000 ----a-w- c:\programme\Microsoft ActiveSync\wcescomm.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
2006-11-17 13:16 50736 ----a-w- c:\programme\Gemeinsame Dateien\aol\1165626455\ee\aolsoftware.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
2005-06-17 06:56 139264 ----a-w- c:\programme\Intel\Intel Matrix Storage Manager\IAAnotif.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2005-06-10 09:44 249856 ----a-w- c:\programme\Gemeinsame Dateien\InstallShield\UpdateService\ISUSPM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2005-06-10 09:44 81920 ----a-w- c:\programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-04-14 09:32 421160 ----a-w- c:\programme\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MemoryCardManager]
2006-06-27 11:34 299008 ----a-w- c:\programme\Dell Photo AIO Printer 926\memcard.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
2005-05-03 07:37 53248 ----a-w- c:\programme\MUSICMATCH\Musicmatch Jukebox\mmtask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
2005-05-03 07:37 135168 ----a-w- c:\programme\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2009-07-26 15:44 3883856 ----a-w- c:\programme\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
2007-09-20 08:51 1836328 ----a-w- c:\programme\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 14:57 153136 ----a-w- c:\programme\Gemeinsame Dateien\Nero\Lib\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Norton Ghost 10.0]
2005-12-07 15:05 1537696 ----a-w- c:\programme\Norton Ghost\Agent\GhostTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 16:38 421888 ----a-w- c:\programme\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2011-01-26 16:05 15026056 ----a-r- c:\programme\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2010-11-27 00:19 1242448 ----a-w- c:\programme\Steam\steam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2009-11-01 10:18 198160 ----a-w- c:\programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WLSetupSvc"=3 (0x3)
"SiteAdvisor Service"=2 (0x2)
"Norton Ghost"=3 (0x3)
"NMIndexingService"=3 (0x3)
"Nero BackItUp Scheduler 3"=2 (0x2)
"gusvc"=2 (0x2)
"de_serv"=3 (0x3)
"ccSetMgr"=2 (0x2)
"ccPwdSvc"=3 (0x3)
"ccEvtMgr"=2 (0x2)
"AOL ACS"=2 (0x2)
"aawservice"=2 (0x2)
"P4P Service"=2 (0x2)
"McrdSvc"=2 (0x2)
"ImapiService"=3 (0x3)
"IDriverT"=3 (0x3)
"helpsvc"=2 (0x2)
"GEARSecurity"=2 (0x2)
"Fax"=2 (0x2)
"BthServ"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programme\\Dell Network Assistant\\ezi_hnm2.exe"=
"c:\\Programme\\Messenger\\msmsgs.exe"=
"c:\\Programme\\Gemeinsame Dateien\\aol\\ACS\\AOLDial.exe"=
"c:\\Programme\\Gemeinsame Dateien\\aol\\ACS\\AOLacsd.exe"=
"c:\\Programme\\AOL 9.0\\waol.exe"=
"c:\\WINDOWS\\system32\\dlcxcoms.exe"=
"c:\\Programme\\PPMate\\ppmate.exe"=
"c:\\Programme\\Gemeinsame Dateien\\aol\\1165626455\\ee\\aolsoftware.exe"=
"c:\\Dokumente und Einstellungen\\aljosa\\Anwendungsdaten\\SopCast\\adv\\SopAdver.exe"=
"c:\\Programme\\TVUPlayer\\TVUPlayer.exe"=
"c:\\Programme\\SopCast\\SopCast.exe"=
"c:\\Programme\\Azureus\\Azureus.exe"=
"c:\\Programme\\Mozilla Firefox\\firefox.exe"=
"c:\\Programme\\TVAnts\\Tvants.exe"=
"c:\programme\Microsoft ActiveSync\rapimgr.exe"= c:\programme\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\programme\Microsoft ActiveSync\wcescomm.exe"= c:\programme\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\programme\Microsoft ActiveSync\WCESMgr.exe"= c:\programme\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Programme\\SopCast\\adv\\SopAdver.exe"=
"c:\\Dokumente und Einstellungen\\aljosa\\Lokale Einstellungen\\Anwendungsdaten\\RayV\\RayV.dll"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\Programme\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programme\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Programme\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Programme\\Ubisoft\\Related Designs\\ANNO 1404\\Anno4.exe"=
"c:\\Programme\\Ubisoft\\Related Designs\\ANNO 1404\\tools\\Anno4Web.exe"=
"c:\\Programme\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programme\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programme\\Steam\\SteamApps\\common\\empire total war\\Empire.exe"=
"c:\\Programme\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Programme\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Programme\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\Programme\\Gemeinsame Dateien\\McAfee\\McSvcHost\\McSvHost.exe"=
"c:\\Programme\\Skype\\Phone\\Skype.exe"=
"c:\\Programme\\Bonjour\\mDNSResponder.exe"=
"c:\\Programme\\iTunes\\iTunes.exe"=
"c:\\Programme\\ICQ7.5\\ICQ.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC
"13972:TCP"= 13972:TCP:BitComet 13972 TCP
"13972:UDP"= 13972:UDP:BitComet 13972 UDP
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
.
R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [2/15/2007 2:02 AM 155136]
R0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [2/15/2007 2:02 AM 5248]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [11/14/2009 5:29 PM 691696]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [8/13/2010 12:29 PM 84200]
R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2010/05/04 01:25];c:\programme\CyberLink\PowerDVD10\NavFilter\000.fcl [3/13/2010 12:58 PM 87536]
R2 hnmwrlspkt;HomeNet Manager Wireless Protocol;c:\windows\system32\drivers\hnm_wrls_pkt.sys [1/12/2006 11:27 PM 13696]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\programme\McAfee\SiteAdvisor\McSACore.exe [11/18/2008 4:54 PM 88176]
R2 McMPFSvc;McAfee Personal Firewall-Dienst;"c:\programme\Gemeinsame Dateien\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [8/13/2010 12:29 PM 271480]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\programme\Gemeinsame Dateien\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [8/13/2010 12:29 PM 271480]
R2 mfefire;McAfee Firewall Core Service;c:\programme\Gemeinsame Dateien\McAfee\SystemCore\mfefire.exe [8/13/2010 12:30 PM 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\programme\Gemeinsame Dateien\McAfee\SystemCore\mfevtps.exe [8/13/2010 12:30 PM 141792]
R2 wsppkt;Wireless Security Protocol;c:\windows\system32\drivers\wsp_pkt.sys [1/12/2006 11:29 PM 13568]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [8/13/2010 12:29 PM 56064]
R3 dlcx_device;dlcx_device;c:\windows\system32\dlcxcoms.exe -service --> c:\windows\system32\dlcxcoms.exe -service [?]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [8/13/2010 12:29 PM 314088]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [8/13/2010 12:29 PM 88736]
R3 SPC620;Philips SPC620NC PC Camera;c:\windows\system32\drivers\SPC620.sys [9/2/2008 4:13 PM 484352]
R3 SPC620m;Philips SPC620NC PC Cameram;c:\windows\system32\drivers\SPC620m.sys [9/2/2008 4:13 PM 7680]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 2:16 PM 130384]
S2 LicCtrlService;LicCtrl Service;c:\windows\Runservice.exe [12/9/2006 8:05 PM 2560]
S3 alcan5ln;Alcatel SpeedTouch(tm) USB ADSL RFC1483 Networking Driver (NDIS);c:\windows\system32\drivers\alcan5ln.sys [10/14/2006 12:18 PM 36048]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [8/13/2010 12:29 PM 88736]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [8/13/2010 12:29 PM 84488]
S3 PDNMp50;PDNMp50 NDIS Protocol Driver;c:\windows\system32\drivers\PDNMp50.sys [11/28/2006 10:46 PM 28224]
S3 PDNSp50;PDNSp50 NDIS Protocol Driver;c:\windows\system32\drivers\PDNSp50.sys [11/28/2006 10:46 PM 27072]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 2:16 PM 753504]
.
--- Andere Dienste/Treiber im Speicher ---
.
*Deregistered* - mfeavfk01
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Inhalt des "geplante Tasks" Ordners
.
2011-05-31 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programme\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://start.icq.com/
uInternet Connection Wizard,ShellNext = hxxp://127.0.0.1:4664/first_usage&s=5h6zyshQVrzsI4x9p28_AQYDGD8
uInternet Settings,ProxyOverride = local
uInternet Settings,ProxyServer = http=127.0.0.1:64889
uSearchURL,(Default) = hxxp://de.search.yahoo.com/search?fr=mcafee&p=%s
IE: &Clean Traces - c:\programme\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\programme\DAP\dapextie.htm
IE: A&lles mit ReGet Deluxe herunterladen - c:\programme\Gemeinsame Dateien\ReGet Shared\CC_All.htm
IE: Download &all with DAP - c:\programme\DAP\dapextie2.htm
IE: Herunterladen mit Re&Get Deluxe - c:\programme\Gemeinsame Dateien\ReGet Shared\CC_Link.htm
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Save YouTube Video as MP3 - c:\programme\Gemeinsame Dateien\DVDVideoSoft\Dll\IEContextMenuY.dll/scriptY2MP3.htm
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\programme\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 192.168.1.1
DPF: {05C1004E-2596-48E5-8E26-39362985EEB9} - hxxp://p3p.sogou.com/MMCShell.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game08.zylom.com/activex/zylomgamesplayer.cab
FF - ProfilePath - c:\dokumente und einstellungen\aljosa\Anwendungsdaten\Mozilla\Firefox\Profiles\gyhyrffy.default\
FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)
FF - prefs.js: browser.startup.homepage - hxxp://start.icq.com/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.1.9&q=
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKU-Default-Run-ONWERETETR.exe - c:\onweretetr.exe\ONWERETETR.exe
MSConfigStartUp-DellSupportCenter - c:\programme\Dell Support Center\bin\sprtcmd.exe
MSConfigStartUp-googletalk - c:\programme\Google\Google Talk\googletalk.exe
MSConfigStartUp-ICQ - c:\programme\ICQ7.1\ICQ.exe
MSConfigStartUp-ICQ Lite - c:\programme\ICQLite\ICQLite.exe
MSConfigStartUp-MSKDetectorExe - c:\programme\McAfee\SpamKiller\MSKDetct.exe
MSConfigStartUp-nwiz - nwiz.exe
MSConfigStartUp-SiteAdvisor - c:\programme\SiteAdvisor\6261\SiteAdv.exe
MSConfigStartUp-SpeedTouch USB Diagnostics - c:\programme\Alcatel\SpeedTouch USB\Dragdiag.exe
MSConfigStartUp-SunJavaUpdateSched - c:\programme\Java\jre1.6.0_05\bin\jusched.exe
AddRemove-Aktuelle Daten - c:\programme\EA SPORTS\FUSSBALL MANAGER 07\Uninstal.exe
AddRemove-NVIDIA Display Control Panel - c:\programme\NVIDIA Corporation\Uninstall\nvuninst.exe
AddRemove-ppmate - c:\programme\PPMate\uninst.exe
AddRemove-Sogou VOD - c:\programme\Sogou PXP\Uninstall.exe
AddRemove-{C0698BDA-0D29-40EE-8570-A31106DF9AB1} - c:\programme\InstallShield Installation Information\{C0698BDA-0D29-40EE-8570-A31106DF9AB1}\Setup.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2011-05-31 17:26
Windows 5.1.2600 Service Pack 3 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCXCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}]
"ImagePath"="\??\c:\programme\CyberLink\PowerDVD10\NavFilter\000.fcl"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3354392262-1568021175-31949345-1005\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:06,be,95,aa,d1,89,ac,e7,1a,f7,86,9d,39,e8,5d,84,57,ef,05,33,63,87,36,
c5,e7,d5,13,c0,86,da,26,6d,1d,4a,a1,5a,c1,d9,0c,eb,04,59,6c,68,19,ae,b2,54,\
"??"=hex:b3,1e,fb,7c,5b,84,eb,80,11,64,8d,1a,07,70,d6,36
.
[HKEY_USERS\S-1-5-21-3354392262-1568021175-31949345-1005\Software\SecuROM\License information*]
"datasecu"=hex:12,02,b7,20,7d,74,92,30,84,31,f8,42,20,b1,6e,4d,5d,68,d4,96,c0,
b4,10,90,9c,24,83,96,cc,7b,9a,7c,bb,5b,d9,6e,2c,d9,9f,ef,30,75,ad,0c,28,68,\
"rkeysecu"=hex:51,f9,7a,3c,14,63,63,49,d7,98,85,e0,60,5a,6b,ee
.
[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \169D180DB7FE8847]
"1"=hex:1a,c6,90,39,73,14,70,4f,c7,99,3b,d6,b3,40,09,16,86,2b,9b,9b,f3,96,a9,
e9
"2"=hex:05,83,26,a9,dc,b6,17,45,de,2e,f0,41,a5,95,91,56,fe,07,ca,23,63,6c,c8,
df,a0,cb,29,a7,07,62,23,54
"3"=hex:1a,c6,90,39,73,14,70,4f,c7,99,3b,d6,b3,40,09,16,39,39,6a,6e,1d,99,29,
0e,9a,9e,61,33,16,37,68,38,ee,25,f6,f1,91,9f,21,a9,58,ec,19,f6,96,30,78,09
.
[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \169D180DB7FE8847\13D3AF07D4AFC792B9BD996AC108D6B5]
"1"=hex:6a,02,e3,17,35,aa,4f,41,58,69,23,a3,81,f4,a8,0e,0a,4e,8a,24,18,b0,7f,
17,12,df,d0,2e,5e,18,49,90,15,18,bd,aa,84,24,4a,2c
"2"=hex:3b,ec,52,ae,03,c1,6c,47
"3"=hex:6a,52,32,35,21,af,63,19,3a,72,10,22,fc,80,b3,9d,61,0d,55,8b,5e,56,38,
62,c6,60,8c,8f,8b,8e,62,ae,53,1e,03,6e,26,4a,65,92,74,53,84,0d,d4,42,60,5c,\
"4"=hex:2f,ad,a2,e7,8a,bf,05,5e
"5"=hex:bf,e5,23,7b,b0,66,d6,fc,b8,e8,6b,a0,96,52,f7,32,80,09,8f,24,b7,b3,55,
1a,98,d1,47,16,02,43,61,1c,b9,d5,8f,2a,7b,81,b1,fb,95,22,f8,b3,2c,53,9d,ae,\
"6"=hex:6a,02,e3,17,35,aa,4f,41,58,69,23,a3,81,f4,a8,0e,0a,4e,8a,24,18,b0,7f,
17,12,df,d0,2e,5e,18,49,90,2f,a8,42,c9,bd,28,bd,03,a4,ed,67,8d,07,a7,03,f5,\
"7"=hex:1a,c6,90,39,73,14,70,4f,c7,99,3b,d6,b3,40,09,16,5c,6c,8a,b0,95,8d,88,
02,5c,f2,b7,9f,8e,b8,9a,b3,47,aa,06,9a,55,51,85,6f,7c,bd,b8,83,41,dc,29,77,\
"8"=hex:9d,9e,b2,b9,a7,a5,f4,ae,d3,52,89,a0,b2,60,4a,5c,bc,7d,5c,3f,11,2f,08,
d9,37,38,fd,5d,e6,6e,24,be,cb,a3,23,c0,b6,a9,d1,5d,58,e0,b7,30,8c,73,2d,a2
"9"=hex:81,20,8f,ab,28,6a,52,9c
"18"=hex:4b,72,8f,bc,6c,3f,e4,15
"10"=hex:55,0c,d6,b4,90,c5,27,45
"11"=hex:81,20,8f,ab,28,6a,52,9c
"12"=hex:b1,6d,29,a6,ab,e0,5c,05,6c,b4,c1,0a,20,16,43,06,75,5f,e0,ab,0b,98,a7,
b6,d9,a3,83,ec,b7,4a,1f,5c,1d,48,d2,1c,64,48,1f,dc,17,32,c1,ca,a9,ab,d6,95,\
"13"=hex:df,8c,e0,33,83,e8,6b,86,cc,62,02,37,5b,de,dc,9e,1a,aa,54,d8,9c,82,e4,
24
"14"=hex:0d,7e,11,86,a7,43,bb,80,cb,84,d6,9b,52,2b,0b,b6
"24"=hex:81,20,8f,ab,28,6a,52,9c
"26"=hex:81,20,8f,ab,28,6a,52,9c
"27"=hex:81,20,8f,ab,28,6a,52,9c
"19"=hex:44,5a,19,92,81,1d,8b,e2,7c,4c,6e,46,26,ad,a8,2e
"22"=hex:81,20,8f,ab,28,6a,52,9c
"15"=hex:84,58,f5,14,e8,f2,3d,b9,69,f4,12,a8,01,0c,20,1b,b0,60,75,21,7e,67,0a,
17,d7,a8,92,08,c1,a8,30,a9,3a,bc,b3,7c,25,01,88,99,74,5f,84,5d,23,c3,8d,b5,\
.
[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \169D180DB7FE8847\CC7B909C85BC507A2CDBC39B09A1A69B]
"1"=hex:6a,02,e3,17,35,aa,4f,41,58,69,23,a3,81,f4,a8,0e,57,fe,fa,3f,01,c1,2c,
1c,5e,e5,91,0b,2f,7e,4c,e7,3c,a9,5c,7c,76,d5,a4,ad
"2"=hex:92,77,56,3a,d4,22,71,61
"3"=hex:a5,83,e8,10,bf,ae,e7,e5,4a,dc,bc,6b,16,2c,6f,00,4d,98,91,7d,bc,87,5e,
8d,30,f5,21,12,7e,8e,e4,97,d9,e1,7c,4f,9a,f7,09,41,0f,d1,db,ca,67,9c,d5,d7,\
"4"=hex:2f,ad,a2,e7,8a,bf,05,5e
"5"=hex:bf,e5,23,7b,b0,66,d6,fc,b8,e8,6b,a0,96,52,f7,32,80,09,8f,24,b7,b3,55,
1a,98,d1,47,16,02,43,61,1c,b9,d5,8f,2a,7b,81,b1,fb,95,22,f8,b3,2c,53,9d,ae,\
"6"=hex:6a,02,e3,17,35,aa,4f,41,58,69,23,a3,81,f4,a8,0e,57,fe,fa,3f,01,c1,2c,
1c,5e,e5,91,0b,2f,7e,4c,e7,67,fa,40,fe,d4,4a,9a,ab,45,85,3e,fe,07,1b,7d,f7,\
"7"=hex:1a,c6,90,39,73,14,70,4f,c7,99,3b,d6,b3,40,09,16,5c,6c,8a,b0,95,8d,88,
02,5c,f2,b7,9f,8e,b8,9a,b3,47,aa,06,9a,55,51,85,6f,7c,bd,b8,83,41,dc,29,77,\
"8"=hex:63,5a,d7,1b,b1,d4,18,46,9d,8a,b3,da,f7,a8,9d,ab,87,a3,2a,ca,13,f6,e4,
c5,41,b1,c1,29,7c,b2,b7,13,8f,1c,0d,5f,4b,3c,0f,fb
"9"=hex:81,20,8f,ab,28,6a,52,9c
"18"=hex:4b,72,8f,bc,6c,3f,e4,15
"10"=hex:81,20,8f,ab,28,6a,52,9c
"11"=hex:81,20,8f,ab,28,6a,52,9c
"12"=hex:da,ff,bd,ce,3e,b8,a3,5e,35,3c,b1,38,a5,16,64,6b,35,b4,61,fe,94,aa,13,
0e,8d,43,fd,48,2d,3a,c1,1f,3f,63,e9,ef,fb,0e,d1,cc,c6,42,55,fd,11,a2,33,cb,\
"13"=hex:37,ce,d7,68,6c,cf,2e,2d,a2,ae,7b,42,9c,a4,27,78,88,80,73,2c,67,28,96,
3d
"14"=hex:0d,f5,4e,44,fe,9e,11,67,d4,ec,25,e7,d8,da,e7,24
"24"=hex:81,20,8f,ab,28,6a,52,9c
"26"=hex:81,20,8f,ab,28,6a,52,9c
"27"=hex:81,20,8f,ab,28,6a,52,9c
"19"=hex:68,c7,ea,bd,e0,2e,98,f0,15,d9,0a,42,7d,db,74,8f
"22"=hex:81,20,8f,ab,28,6a,52,9c
"15"=hex:60,e4,4f,3e,bf,8f,64,1a,f3,0b,fe,60,c3,be,57,c5,06,48,6c,0f,eb,e3,3b,
ad,83,45,f6,2e,8b,f1,bf,fb,b1,41,26,58,82,c8,73,d9,71,0b,7d,6d,5f,7f,f9,50,\
.
[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \F93383AA3238BCCB]
"1"=hex:47,af,e3,b9,38,4b,f6,e6,cb,8b,59,0c,3a,af,c5,a2,d6,9f,52,ce,23,dc,1a,
c2
"2"=hex:d1,c8,c3,5e,08,10,b9,8f,1e,fd,a6,7c,f5,6d,b0,f3,a6,71,8f,f8,ab,bd,bd,
76,64,10,04,f0,92,77,f9,20
"3"=hex:47,af,e3,b9,38,4b,f6,e6,cb,8b,59,0c,3a,af,c5,a2,ac,98,11,9b,be,95,83,
07,ae,ba,7e,d8,e6,d6,56,50,c4,dc,bb,7b,18,78,a4,de,04,5c,25,4e,9f,d7,39,6d
.
[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \F93383AA3238BCCB\86F50A4E3D8BE88AF84CD03B1C57A42C]
"1"=hex:0e,99,cd,9c,6f,50,13,a2,82,70,40,54,38,93,8f,c5,05,f3,da,4d,e8,82,d5,
04,c7,c6,1f,bf,24,f4,89,65
"2"=hex:c6,c1,1a,2b,99,40,bf,93
"3"=hex:c3,66,af,b0,a0,e0,c6,a9,63,10,c6,48,d9,4f,88,5b,aa,63,55,95,f1,79,71,
44,d9,0a,da,93,32,fd,5e,be,84,4d,52,24,78,18,77,41,35,7b,23,08,38,3e,2e,39,\
"4"=hex:2f,ad,a2,e7,8a,bf,05,5e
"5"=hex:bf,e5,23,7b,b0,66,d6,fc,b8,e8,6b,a0,96,52,f7,32,80,09,8f,24,b7,b3,55,
1a,98,d1,47,16,02,43,61,1c,b9,d5,8f,2a,7b,81,b1,fb,95,22,f8,b3,2c,53,9d,ae,\
"6"=hex:0e,99,cd,9c,6f,50,13,a2,82,70,40,54,38,93,8f,c5,05,f3,da,4d,e8,82,d5,
04,26,28,49,41,45,1c,d1,d9,35,f2,a5,89,f8,17,cf,bb,05,0a,e8,c2,d7,eb,32,27,\
"7"=hex:3b,e8,2f,01,6c,32,33,d8,e1,d7,f3,f6,0e,0a,fa,46,62,39,09,43,d3,da,73,
d4,4e,db,d0,f9,b1,fb,0a,f1,d3,99,57,af,7d,98,93,fd,a5,1e,64,b6,5b,35,28,e1,\
"8"=hex:63,5a,d7,1b,b1,d4,18,46,0a,a7,b3,1c,99,c8,a4,fc,8e,d5,91,06,69,a2,b1,
d4,43,1a,b5,55,45,f6,c7,e7,86,ad,47,d1,f0,33,03,e9
"9"=hex:81,20,8f,ab,28,6a,52,9c
"18"=hex:4b,72,8f,bc,6c,3f,e4,15
"10"=hex:81,20,8f,ab,28,6a,52,9c
"11"=hex:81,20,8f,ab,28,6a,52,9c
"12"=hex:dc,45,40,84,57,1b,79,e4,d0,24,75,41,57,cc,20,c0,6b,2d,8e,ca,8b,e1,ce,
79,e9,e9,b0,76,8d,95,66,d7,df,92,75,8e,22,33,61,b3,a4,6e,dc,5a,87,b7,0c,f8,\
"13"=hex:0c,6f,68,72,87,31,21,d5,dd,c8,32,28,a5,14,12,92,86,57,aa,6f,13,2b,d7,
85
"14"=hex:fa,ee,90,bf,e3,32,08,6b
"24"=hex:81,20,8f,ab,28,6a,52,9c
"26"=hex:81,20,8f,ab,28,6a,52,9c
"27"=hex:81,20,8f,ab,28,6a,52,9c
"19"=hex:3c,03,20,ae,88,96,ff,6a,c4,fa,e2,d2,58,fc,9d,65
"22"=hex:81,20,8f,ab,28,6a,52,9c
"15"=hex:2e,eb,4e,00,39,bc,d3,67,32,3d,d3,3e,4c,a9,1b,0c,d5,0d,cc,c6,7b,b6,09,
3e,e5,80,68,85,fd,ed,26,d4,c7,a3,6f,a5,c5,de,aa,05,bd,31,d9,4f,b2,48,35,e3,\
.
[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \F93383AA3238BCCB\CAE36273CE2083AC10451E2C33E7B63B]
"1"=hex:7e,63,ed,e4,ff,c6,da,b0,3c,b3,ff,e0,03,2b,bc,b2,7f,b3,d1,39,03,20,a9,
47,94,35,3b,94,b4,9c,b2,85
"2"=hex:82,9d,b7,04,75,a2,e0,2a
"3"=hex:93,93,9b,2f,ee,5f,ba,0c,f9,e4,43,b1,d9,23,74,86,67,3c,6b,1f,29,bd,f3,
1b,d1,a5,1a,44,d7,91,76,0a,53,4c,f7,fb,89,3f,d7,c3,5f,25,7d,32,a2,1e,41,f5,\
"4"=hex:2f,ad,a2,e7,8a,bf,05,5e
"5"=hex:bf,e5,23,7b,b0,66,d6,fc,b8,e8,6b,a0,96,52,f7,32,80,09,8f,24,b7,b3,55,
1a,98,d1,47,16,02,43,61,1c,b9,d5,8f,2a,7b,81,b1,fb,95,22,f8,b3,2c,53,9d,ae,\
"6"=hex:7e,63,ed,e4,ff,c6,da,b0,3c,b3,ff,e0,03,2b,bc,b2,7f,b3,d1,39,03,20,a9,
47,f1,92,06,65,96,dc,6f,e5,35,a3,48,e9,ad,a9,09,86,11,e5,84,b3,49,30,20,0e,\
"7"=hex:3b,e8,2f,01,6c,32,33,d8,e1,d7,f3,f6,0e,0a,fa,46,62,39,09,43,d3,da,73,
d4,4e,db,d0,f9,b1,fb,0a,f1,d3,99,57,af,7d,98,93,fd,a5,1e,64,b6,5b,35,28,e1,\
"8"=hex:63,5a,d7,1b,b1,d4,18,46,0a,a7,b3,1c,99,c8,a4,fc,cd,df,f6,b8,74,18,fa,
dd,30,dc,88,59,2a,92,45,f1,bd,1f,b7,30,80,7d,13,f4
"9"=hex:81,20,8f,ab,28,6a,52,9c
"18"=hex:4b,72,8f,bc,6c,3f,e4,15
"10"=hex:81,20,8f,ab,28,6a,52,9c
"11"=hex:81,20,8f,ab,28,6a,52,9c
"12"=hex:b0,0f,05,88,4b,2a,68,b5,64,c6,95,e1,a4,8c,21,9c,ec,23,db,c1,85,7a,49,
8c,17,91,03,09,39,96,20,32,76,c1,9b,62,61,a8,a5,a2,c4,3f,b9,3b,f6,9b,cc,a7,\
"13"=hex:b5,a2,a0,c9,4b,df,a6,a1,49,18,14,df,c7,0b,c7,32,37,09,1d,99,99,9e,2b,
85
"14"=hex:65,7c,b7,01,2e,2f,77,f5
"24"=hex:81,20,8f,ab,28,6a,52,9c
"26"=hex:81,20,8f,ab,28,6a,52,9c
"27"=hex:81,20,8f,ab,28,6a,52,9c
"19"=hex:fc,7f,3b,b5,5f,ec,63,d6,3b,f2,9f,93,93,a3,46,03
"22"=hex:81,20,8f,ab,28,6a,52,9c
"15"=hex:53,b6,bc,5a,f6,3a,0b,9d,e6,ff,dc,fb,f2,fc,fc,3b,a1,ec,37,61,d4,f9,54,
17,17,6e,de,f1,47,b7,23,99,9b,db,6f,e9,69,13,ff,ce,56,4c,a0,58,f5,8c,65,9f,\
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'explorer.exe'(4120)
c:\progra~1\mcafee\SITEAD~1\saHook.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\programme\Bonjour\mDNSResponder.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\programme\Intel\Intel Matrix Storage Manager\iaantmon.exe
c:\programme\Java\jre6\bin\jqs.exe
c:\programme\Gemeinsame Dateien\McAfee\SystemCore\mcshield.exe
c:\programme\Windows Media Player\WMPNetwk.exe
c:\windows\stsystra.exe
c:\windows\system32\RUNDLL32.EXE
c:\progra~1\MICROS~4\rapimgr.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\rundll32.exe
c:\programme\Skype\Plugin Manager\skypePM.exe
c:\programme\iPod\bin\iPodService.exe
c:\programme\Alice\Signup\AliceCnn.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\dlcxcoms.exe
c:\progra~1\mcafee\VIRUSS~1\mcvsshld.exe
c:\progra~1\mcafee\VIRUSS~1\mcvsmap.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2011-05-31 17:34:56 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2011-05-31 15:34
.
Vor Suchlauf: 24 Verzeichnis(se), 30,132,113,408 Bytes frei
Nach Suchlauf: 25 Verzeichnis(se), 31,427,252,224 Bytes frei
.
WindowsXP-KB310994-SP2-Pro-BootDisk-DEU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
.
- - End Of File - - B548AFD9B3674B98F8200EB09DF24FA4 |