| | Ab und zu keine Seiten aufrufbar. Hallo,
danke für die schnelle Antwort, hier die Auswertung: ComboFix: Zitat:
ComboFix 08-01-23.2 - ***** 2008-01-24 17:51:45.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1031.18.1671 [GMT 1:00]
ausgeführt von:: C:\Dokumente und Einstellungen\*****\Desktop\ComboFix.exe
* Neuer Wiederherstellungspunkt wurde erstellt WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((( Dateien erstellt von 2007-12-24 bis 2008-01-24 ))))))))))))))))))))))))))))))
.
2008-01-24 17:51 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\Nircmd.exe
2008-01-22 14:42 . 2008-01-22 14:42 <DIR> d-------- C:\Programme\Sony
2008-01-22 14:42 . 2008-01-23 17:41 <DIR> d-------- C:\Programme\Pirates of the Burning Sea
2008-01-20 13:11 . 2008-01-20 13:11 <DIR> d-------- C:\Programme\Java
2008-01-20 13:11 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-01-20 13:10 . 2008-01-20 13:10 <DIR> d-------- C:\Programme\Gemeinsame Dateien\Java
2008-01-12 12:06 . 2008-01-12 12:06 <DIR> d-------- C:\Programme\Sygate
2008-01-12 12:06 . 2004-02-02 12:06 83,096 --a------ C:\WINDOWS\system32\SSSensor.dll
2008-01-12 12:06 . 2004-02-02 10:51 55,891 --a------ C:\WINDOWS\system32\drivers\Teefer.sys
2008-01-12 12:06 . 2004-02-02 10:53 18,518 --a------ C:\WINDOWS\system32\drivers\wpsdrvnt.sys
2008-01-12 12:06 . 2004-02-02 10:37 11,914 --a------ C:\WINDOWS\system32\drivers\wg3n.sys
2007-12-24 20:55 . 2007-12-24 20:55 <DIR> d-------- C:\Programme\Logitech
2007-12-24 20:55 . 2007-12-24 20:55 <DIR> d-------- C:\Programme\Gemeinsame Dateien\Logitech
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-22 13:42 --------- d--h--w C:\Programme\InstallShield Installation Information
2007-12-23 19:32 --------- d-----w C:\Programme\Gemeinsame Dateien\Nero
2007-12-23 19:28 --------- d-----w C:\Programme\Gemeinsame Dateien\Ahead
2007-12-23 19:28 --------- d-----w C:\Programme\Ahead
2007-12-23 19:09 278,984 ----a-w C:\WINDOWS\system32\drivers\atksgt.sys
2007-12-06 14:46 --------- d-----w C:\Programme\AGEIA Technologies
2007-12-06 14:44 --------- d-----w C:\Programme\Gemeinsame Dateien\Wise Installation Wizard
2007-12-01 13:11 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
2007-11-07 09:27 729,600 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-10-29 22:42 1,293,312 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
.
(((((((((((((((((((((((((((( Autostart Punkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Hinweis* leere Eintrage & legitime Standardeintrage werden nicht angezeigt.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TuneUp MemOptimizer"="C:\Programme\TuneUp Utilities 2006\MemOptimizer.exe" [2006-10-02 18:58 305152]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:57 15360]
"SpybotSD TeaTimer"="C:\Programme\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Launch LGDCore"="C:\Programme\Gemeinsame Dateien\Logitech\G-series Software\LGDCore.exe" [2006-07-23 02:22 1126400]
"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2004-02-24 16:35 2372760]
"avgnt"="C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe" [2007-10-10 15:16 249896]
"SunJavaUpdateSched"="C:\Programme\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-03 23:57 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="C:\\WINDOWS\\system32\\logonui.exe"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
"Steam"="C:\Programme\Steam\Steam.exe" -silent
"MSMSGS"="C:\Programme\Messenger\msmsgs.exe" /background
"DAEMON Tools"="C:\Programme\DAEMON Tools\daemon.exe" -lang 1033
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="C:\Programme\Java\jre1.5.0_08\bin\jusched.exe"
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe
"StartCCC"=C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
R2 UxTuneUp;TuneUp Designerweiterung;C:\WINDOWS\System32\svchost.exe [2004-08-03 23:58]
S3 ADM8511;ADMtek ADM8511/AN986-USB-Fast Ethernetkonvertierer;C:\WINDOWS\system32\DRIVERS\ADM8511.SYS [2001-08-17 11:11]
S3 BRGSp50;BRGSp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\BRGSp50.sys [2005-06-08 18:44]
S3 ZD1211BU(ZyDAS);ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS);C:\WINDOWS\system32\DRIVERS\zd1211Bu.sys [2005-08-17 14:43]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
*Newly Created Service* - PROCEXP90
.
Inhalt des "geplante Tasks" Ordners
"2008-01-18 16:26:18 C:\WINDOWS\Tasks\1-Klick-Wartung.job"
- C:\Programme\TuneUp Utilities 2006\SystemOptimizer.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-24 17:54:04
Windows 5.1.2600 Service Pack 2 NTFS
Scanne versteckte Prozesse...
Scanne versteckte Autostart Einträge...
Scanne versteckte Dateien...
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
**************************************************************************
| Filelist: Zitat: Verzeichnis von C:\
2008-01-24 17:23 2,145,386,496 pagefile.sys
2008-01-16 17:10 0 DBS.TXT
2008-01-07 16:35 719 moduleName.txt
2007-12-27 16:13 413 boot.ini
2006-10-20 17:17 47,564 NTDETECT.COM
----------------------------------------------------- Verzeichnis von C:\WINDOWS\system32
2008-01-24 17:24 2,206 wpa.dbl
2008-01-20 13:11 5,686 jupdate-1.6.0_03-b05.log
2008-01-02 19:21 17,642,616 MRT.exe
2007-12-12 19:44 387,268 TZLog.log
----------------------------------------------------- Verzeichnis von C:\WINDOWS
2008-01-24 17:54 227 system.ini
2008-01-24 17:28 1,892,920 WindowsUpdate.log
2008-01-24 17:24 0 0.log
2008-01-24 17:24 2,048 bootstat.dat
2008-01-23 19:14 32,644 SchedLgU.Txt
2008-01-22 14:51 395,845 DirectX.log
2008-01-20 16:07 116 NeroDigital.ini
2008-01-19 19:29 50 wiaservc.log
2008-01-19 19:29 416 wiadebug.log
2008-01-19 19:20 972,033 setupapi.log
2008-01-17 19:23 30 Iedit_.INI
2008-01-09 19:47 344,102 tsoc.log
2008-01-09 19:47 298,133 comsetup.log
2008-01-09 19:47 1,355 imsins.log
2008-01-09 19:47 182,230 ntdtcsetup.log
2008-01-09 19:47 48,524 ocmsn.log
2008-01-09 19:47 137,946 iis6.log
2008-01-09 19:47 12,903 KB941644.log
2008-01-09 19:47 44,840 msgsocm.log
2008-01-09 19:47 447,094 ocgen.log
2008-01-09 19:47 870,064 FaxSetup.log
2008-01-09 19:47 1,355 imsins.BAK
2008-01-09 19:47 12,802 KB943485.log
2008-01-06 13:51 13,532 DPINST.LOG
2007-12-24 20:53 188,284 setupact.log
2007-12-21 14:28 73,380 wmsetup.log
----------------------------------------------------- Verzeichnis von C:\WINDOWS\Prefetch*
2008-01-24 18:04 22,598 CMD.EXE-087B4001.pf
2008-01-24 18:04 45,572 NOTEPAD.EXE-336351A9.pf
2008-01-24 17:59 71,446 WMIPRVSE.EXE-28F301A9.pf
2008-01-24 17:59 32,458 WSCRIPT.EXE-32960AB9.pf
2008-01-24 17:57 11,390 FIND.EXE-0EC32F1E.pf
2008-01-24 17:57 145,800 WINRAR.EXE-3588DFE8.pf
2008-01-24 17:56 77,360 IEXPLORE.EXE-2CA9778D.pf
2008-01-24 17:56 16,776 VERCLSID.EXE-3667BD89.pf
2008-01-24 17:56 47,834 SMC.EXE-0B61F84B.pf
2008-01-24 17:55 82,184 FIREFOX.EXE-1D57670A.pf
2008-01-24 17:54 27,844 LISTDLLS.CFEXE-163777B3.pf
2008-01-24 17:54 25,074 CATCHME.CFEXE-0F2A0789.pf
2008-01-24 17:54 8,526 KMD.EXE-32C45867.pf
2008-01-24 17:54 21,780 DUMPHIVE.CFEXE-2ED3B134.pf
2008-01-24 17:54 3,590 GSAR.CFEXE-156760D9.pf
2008-01-24 17:54 10,900 SORT.EXE-194AE83C.pf
2008-01-24 17:54 28,550 CSCRIPT.EXE-1C26180C.pf
2008-01-24 17:54 81,420 EXPLORER.EXE-082F38A9.pf
2008-01-24 17:54 64,992 VFIND.EXE-0CB9A64E.pf
2008-01-24 17:54 12,706 REGEDIT.EXE-1B606482.pf
2008-01-24 17:54 12,824 REGT.CFEXE-15DB5DAE.pf
2008-01-24 17:54 20,750 IPCONFIG.EXE-2395F30B.pf
2008-01-24 17:53 7,506 SWSC.CFEXE-3B4FE4FE.pf
2008-01-24 17:53 4,174 HANDLE.CFEXE-13427ED2.pf
2008-01-24 17:53 11,838 FINDSTR.EXE-0CA6274B.pf
2008-01-24 17:53 9,706 NIRCMD.EXE-2C39EF53.pf
2008-01-24 17:53 4,158 SED.CFEXE-268D7E58.pf
2008-01-24 17:53 7,354 SWREG.CFEXE-2BF4FFCD.pf
2008-01-24 17:53 4,676 MTEE.CFEXE-1E067BC7.pf
2008-01-24 17:53 8,694 NIRCMD.CFEXE-19FF4781.pf
2008-01-24 17:53 2,870 VFIND.CFEXE-2033727F.pf
2008-01-24 17:53 3,828 GREP.CFEXE-20443039.pf
2008-01-24 17:53 14,410 ATTRIB.EXE-39EAFB02.pf
2008-01-24 17:51 10,070 NIRCMD.COM-323C21EC.pf
2008-01-24 17:51 3,962 SF.CFEXE-164B3B2D.pf
2008-01-24 17:51 20,650 SETPATH.CFEXE-034E3D26.pf
2008-01-24 17:51 15,202 ROUTE.EXE-371D32DE.pf
2008-01-24 17:51 53,626 ERUNT.CFEXE-039977DB.pf
2008-01-24 17:51 48,534 COMBOFIX.EXE-11C787DE.pf
2008-01-24 17:51 8,560 SWXCACLS.CFEXE-365F7973.pf
2008-01-24 17:34 77,154 MSIMN.EXE-0B61806C.pf
2008-01-24 17:26 38,316 UPDATE.EXE-13D57D76.pf
2008-01-24 17:26 15,360 PREUPD.EXE-358AA1C1.pf
2008-01-24 17:25 68,058 WUAUCLT.EXE-399A8E72.pf
2008-01-24 17:25 988,794 NTOSBOOT-B00DFAAD.pf
2008-01-23 19:13 18,062 LOGONUI.EXE-0AF22957.pf
2008-01-23 17:42 60,354 POTBS.EXE-02094334.pf
2008-01-23 17:42 106,938 LP_PLUGIN.EXE-1662A542.pf
2008-01-23 17:41 31,776 LAUNCHPAD.EXE-37B489EC.pf
2008-01-23 17:41 42,238 PLAYPOTBS.EXE-1232FA0C.pf
2008-01-23 15:19 21,012 RSD.EXE-206CDBA4.pf
2008-01-23 15:03 83,800 AVNOTIFY.EXE-22AE9451.pf
2008-01-22 17:49 26,918 DRWTSN32.EXE-2B4B52AC.pf
2008-01-22 17:49 34,800 DWWIN.EXE-30875ADC.pf
2008-01-22 16:48 69,704 DFRGNTFS.EXE-269967DF.pf
2008-01-22 16:48 16,970 DEFRAG.EXE-273F131E.pf
2008-01-22 16:31 281,188 Layout.ini
2008-01-22 14:56 12,464 RUNDLL32.EXE-451FC2C0.pf
2008-01-22 14:51 12,824 DXSETUP.EXE-2019BC26.pf
2008-01-22 14:49 2,506 NOAUTORUN.EXE-35264DD4.pf
2008-01-22 14:42 16,828 SETUP.EXE-24E42404.pf
2008-01-22 14:42 15,040 SETUP.EXE-393E66AE.pf
2008-01-22 14:40 93,762 MSIEXEC.EXE-2F8A8CAE.pf
2008-01-22 14:40 60,194 UNINSTALLMANAGER.EXE-1BD98C04.pf
2008-01-22 14:40 49,194 INTEGRATOR.EXE-1C936896.pf
2008-01-22 14:39 65,926 RUNDLL32.EXE-13404D23.pf
2008-01-22 14:36 31,122 SETUP.EXE-2E1AAB89.pf
2008-01-22 14:36 21,002 SETUP.EXE-2592FD0D.pf
2008-01-22 14:35 13,442 SETUP.EXE-397F77E3.pf
2008-01-22 14:33 76,488 WINAMP.EXE-08C38ED9.pf
2008-01-22 11:21 46,416 HELPSVC.EXE-2878DDA2.pf
2008-01-21 10:57 7,978 JAVA.EXE-0967259C.pf
2008-01-20 18:04 64,684 RUNDLL32.EXE-2576181F.pf
2008-01-20 16:44 33,562 DIVXSM.EXE-3407AB62.pf
2008-01-20 16:44 55,894 WMPLAYER.EXE-0996933A.pf
2008-01-20 16:40 53,434 AVCENTER.EXE-37584419.pf
2008-01-20 16:27 19,574 GUARDGUI.EXE-1BD45C30.pf
2008-01-20 14:04 24,660 HIJACKTHIS.EXE-06CDFFEB.pf
2008-01-20 13:08 18,794 TASKMGR.EXE-20256C55.pf
2008-01-20 13:05 17,036 NGEN.EXE-38021CCC.pf
2008-01-20 13:05 19,518 MSCORSVW.EXE-1BF30400.pf
2008-01-20 12:45 27,634 MSMSGS.EXE-32066BA5.pf
2008-01-20 12:15 58,182 STEAM.EXE-25824B4E.pf
2008-01-20 12:10 38,446 CSC.EXE-01730C27.pf
2008-01-20 12:10 10,158 CVTRES.EXE-2329DCD5.pf
2008-01-19 19:34 55,836 AVGNT.EXE-36CA4640.pf
*keine älteren Einträge vorhanden
----------------------------------------------------- Verzeichnis von C:\WINDOWS\tasks
2008-01-24 17:24 6 SA.DAT
2008-01-18 17:26 396 1-Klick-Wartung.job
----------------------------------------------------- Verzeichnis von C:\WINDOWS\temp
---Leer---
----------------------------------------------------- Verzeichnis von C:\DOKUME~1\*****\LOKALE~1\Temp
2008-01-24 18:04 120,989 filelist.txt
2008-01-24 17:29 1,340 jusched.log
2008-01-22 20:00 1,286 java_install_reg.log
2008-01-22 17:48 16,384 ~DF98FD.tmp
2008-01-22 17:32 16,384 ~DF1C5E.tmp
2008-01-22 17:32 16,384 ~DFB40.tmp
2008-01-22 17:32 16,384 ~DF883D.tmp
2008-01-20 13:11 0 java_install.log
2008-01-20 13:10 1,199 jinstall.cfg
2008-01-20 13:06 15,246 dd_vjredist20UI6F66.txt
2008-01-20 13:06 4,069,016 dd_vjredist20MSI6F66.txt
2008-01-20 00:08 2,352 633363845004062500.ccf
2008-01-19 21:47 2,352 633363760391406250.ccf
2008-01-19 21:42 2,352 633363757325156250.ccf
2008-01-19 21:37 2,352 633363754322031250.ccf
2008-01-18 21:12 4,128 633362875645937500.ccf
2008-01-18 21:12 4,656 633362875423281250.ccf
2008-01-18 21:12 4,128 633362875237343750.ccf
2008-01-18 21:11 4,112 633362875013593750.ccf
2008-01-18 14:49 8,822 zackwikieu.rsdf
2008-01-18 13:00 16,384 Perflib_Perfdata_854.dat
| Silentrunners Logfile im unterem Beitrag |