der zweite Teil :
Code:
Alles auswählen Aufklappen ATTFilter
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-26 10:30 . 2009-05-20 19:46 -------- d-----w- c:\programme\QuickTime
2009-09-25 16:48 . 2007-05-02 17:26 -------- d-----w- c:\programme\Gemeinsame Dateien\Adobe
2009-09-24 19:48 . 2008-11-25 17:02 -------- d-----w- c:\programme\Trend Micro
2009-09-23 15:56 . 2006-12-16 21:45 -------- d-----w- c:\programme\Yahoo!
2009-09-23 15:56 . 2006-12-14 20:56 -------- d-----w- c:\programme\Gemeinsame Dateien\ACD Systems
2009-09-23 15:50 . 2006-12-16 13:05 -------- d-----w- c:\programme\Microsoft Picture It! PhotoPub
2009-09-22 15:52 . 2008-06-14 09:54 -------- d-----w- c:\programme\Azureus
2009-09-21 17:34 . 2007-01-24 14:33 -------- d-----w- c:\programme\Opera
2009-09-15 14:19 . 2004-08-04 12:00 84674 ----a-w- c:\windows\system32\perfc007.dat
2009-09-15 14:19 . 2004-08-04 12:00 459154 ----a-w- c:\windows\system32\perfh007.dat
2009-09-13 10:53 . 2009-09-13 10:53 -------- d-----w- c:\programme\PC Inspector File Recovery
2009-09-13 10:53 . 2006-09-18 04:39 -------- d--h--w- c:\programme\InstallShield Installation Information
2009-09-13 10:32 . 2008-02-09 12:30 1925024 ----a-w- c:\programme\install_flash_player.exe
2009-09-12 14:04 . 2008-05-04 18:27 -------- d-----w- c:\programme\Windows Live
2009-09-12 10:46 . 2009-09-12 10:55 1835 ----a-w- c:\programme\iP2200 Handbuchausgabe für den Bildschirm.lnk
2009-09-12 10:11 . 2006-12-16 11:35 -------- d-----w- c:\programme\3Planesoft Screensaver Manager
2009-09-12 10:11 . 2007-10-27 23:38 -------- d-----w- c:\programme\The One Ring 3D Screensaver
2009-09-12 10:00 . 2006-12-15 13:54 -------- d-----w- c:\programme\Ahead
2009-09-10 16:29 . 2006-12-14 19:49 -------- d-----w- c:\windows\system32\config\systemprofile\Anwendungsdaten\Symantec
2009-09-10 15:06 . 2006-12-14 21:01 -------- d-----w- c:\programme\T-Online
2009-09-10 14:49 . 2009-09-10 14:49 21740 ----a-w- c:\windows\system32\emptyregdb.dat
2009-08-31 13:10 . 2006-12-14 19:49 67344 ----a-w- c:\dokumente und einstellungen\Panther\Lokale Einstellungen\Anwendungsdaten\GDIPFONTCACHEV1.DAT
2009-08-14 04:58 . 2009-09-24 20:15 7396 ----a-w- c:\windows\system32\drivers\pctcore.cat
2009-07-26 14:44 . 2009-07-26 14:44 48448 ----a-w- c:\windows\system32\sirenacm.dll
2009-07-12 10:21 . 2004-08-04 12:00 233472 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-10 11:10 . 2009-07-10 11:10 307568 ----a-w- c:\windows\WLXPGSS.SCR
2009-05-20 19:54 . 2009-03-20 07:37 19387336 ----a-w- c:\programme\DivXInstaller.exe
2009-03-26 19:00 . 2009-03-26 19:30 2592 ----a-w- c:\programme\updateLog.txt
2009-03-26 19:00 . 2009-03-26 19:30 512 ----a-w- c:\programme\outdated.dat
2009-03-26 19:00 . 2009-03-26 19:30 1084529 ----a-w- c:\programme\JDownloader.jar
2009-03-26 19:00 . 2009-03-26 19:30 1029903 ----a-w- c:\programme\jdupdate.jar
2009-03-26 18:46 . 2009-03-26 19:30 1136 ----a-w- c:\programme\p230309_bd_s01.dlc
2009-03-26 18:46 . 2009-03-26 19:30 496 ----a-w- c:\programme\p230309_bd_s01.ccf
2009-03-26 18:46 . 2009-03-26 19:30 172 ----a-w- c:\programme\p230309_bd_s01.rsdf
2009-03-19 20:42 . 2009-03-20 07:37 34543112 ----a-w- c:\programme\Ad-AwareAE.exe
2009-03-17 20:41 . 2009-03-20 07:37 4701448 ----a-w- c:\programme\GOMPLAYERENSETUP.EXE
2009-03-11 21:23 . 2009-03-26 19:30 32069 ----a-w- c:\programme\license.txt
2009-03-11 21:23 . 2009-03-26 19:30 34816 ----a-w- c:\programme\JDownloader.exe
2008-11-25 17:02 . 2008-11-30 11:42 812344 ----a-w- c:\programme\HJTInstall.exe
2008-11-25 16:58 . 2008-11-30 11:42 607640 ----a-w- c:\programme\jxpiinstall-6u10-fcs-bin-b92-windows-i586-09_nov_2008.exe
2008-08-10 17:40 . 2008-11-30 11:42 1827729 ----a-w- c:\programme\avisampl.exe
2008-08-08 12:27 . 2008-11-30 11:42 756405 ----a-w- c:\programme\NetlogPhotoToolInstaller.exe
2008-06-29 16:02 . 2007-08-24 06:58 445424 ----a-w- c:\programme\msgr8de.exe
2008-06-14 09:40 . 2008-07-20 10:01 8136200 ----a-w- c:\programme\Azureus_3.0.5.2a_windows.exe
2008-06-07 13:19 . 2008-07-20 10:00 5692952 ----a-w- c:\programme\opbsetup.exe
2008-05-25 11:31 . 2008-07-20 10:00 3772421 ----a-w- c:\programme\BilderHerunterlader163Setup.exe
2008-05-18 13:17 . 2008-07-20 09:59 6104632 ----a-w- c:\programme\picasaweb-current-setup.exe
2008-05-04 18:27 . 2008-06-29 15:25 2404880 ----a-w- c:\programme\WLinstaller.exe
2008-04-29 18:40 . 2008-05-19 19:40 1570 ----a-w- c:\programme\install.rdf
2008-04-02 15:44 . 2008-07-20 09:59 19512984 ----a-w- c:\programme\SafariSetup.exe
2008-03-23 19:32 . 2008-07-20 10:01 14782496 ----a-w- c:\programme\IE7-WindowsXP-x86-deu.exe
2008-03-02 20:11 . 2008-05-19 19:40 1776 ----a-w- c:\programme\chrome.manifest
2008-02-07 22:17 . 2008-02-07 22:17 21364592 ----a-w- c:\programme\aaw2007.exe
2008-01-18 13:18 . 2008-02-09 12:30 8849866 ----a-w- c:\programme\seamonkey-1.1.7.de-AT.win32.installer.exe
2007-07-24 21:28 . 2006-12-14 23:50 17976688 ----a-w- c:\programme\Install_Messenger.exe
2007-07-15 09:35 . 2007-08-24 06:58 1449865 ----a-w- c:\programme\wrar370d.exe
2007-07-08 14:56 . 2007-08-24 06:59 3480997 ----a-w- c:\programme\BitWiseSetup.exe
2007-07-08 12:10 . 2007-08-24 06:59 18967898 ----a-w- c:\programme\klmcodec102.exe
2007-06-09 08:05 . 2007-08-24 07:00 8789356 ----a-w- c:\programme\seamonkey-1.1.2.de-AT.win32.installer.exe
2007-05-27 20:59 . 2007-05-29 13:45 10873928 ----a-w- c:\programme\InstallIMVU_374.0_full.exe
2007-05-04 18:47 . 2007-05-29 13:45 305566 ----a-w- c:\programme\hj_split.rar
2007-03-01 19:13 . 2007-05-29 13:44 544877 ----a-w- c:\programme\VPlayer-Setup.exe
2007-02-28 20:25 . 2007-05-29 13:44 5624416 ----a-w- c:\programme\WEBDE_Messenger_Setup.exe
2007-02-23 17:14 . 2007-05-29 13:44 2718720 ----a-w- c:\programme\TweakPower1221.exe
2007-02-01 17:02 . 2007-05-29 13:45 313344 ----a-w- c:\programme\hjsplit.exe
2006-12-17 13:20 . 2006-12-17 13:20 11061114 ----a-w- c:\programme\seamonkey-1.0.6.de-AT.win32.installer.exe
2006-12-17 13:17 . 2006-12-17 13:17 8465887 ----a-w- c:\programme\mozilla-1.7.13.de-AT.win32.installer.exe
2006-12-16 21:38 . 2006-12-16 21:38 10376696 ----a-w- c:\programme\ymsgr8us.exe
2006-12-15 21:47 . 2006-12-15 21:46 4910532 ----a-w- c:\programme\Sweepi5.2.20_full_Setup_DE.exe
2006-12-15 21:46 . 2006-12-15 21:46 2727175 ----a-w- c:\programme\autostartmanager-setup.exe
2006-12-15 14:05 . 2006-12-15 14:03 14464888 ----a-w- c:\programme\antivir_workstation_win7u_de_h.exe
2006-12-14 23:48 . 2006-12-14 23:48 1530640 ----a-w- c:\programme\Hello651.exe
2006-09-07 05:03 . 2008-11-30 11:41 4387728 ----a-w- c:\programme\eesetup.exe
2006-04-03 11:54 . 2007-08-24 06:59 1181812 ----a-w- c:\programme\flvplayer_setup.exe
2006-03-07 12:49 . 2008-08-03 10:40 253223 ----a-w- c:\programme\screensaver3.swf
2006-03-07 12:45 . 2008-08-03 10:40 373932 ----a-w- c:\programme\screensaver2.swf
2006-03-07 12:20 . 2008-08-03 10:40 1364480 ----a-w- c:\programme\screensaver1.scr
2004-11-16 15:07 . 2006-12-16 11:35 2255074 ----a-w- c:\programme\the_one_ring.exe
2003-01-21 18:59 . 2006-12-16 12:09 86016 ----a-w- c:\programme\ClearProg.exe
2001-12-29 12:17 . 2007-08-24 06:59 448512 ----a-w- c:\programme\mspt32install.exe
2000-07-14 17:41 . 2009-09-12 09:44 15375 ----a-w- c:\programme\wkhlpqms.hlp
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\programme\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\programme\mozilla firefox\plugins\ssldivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\programme\opera\program\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\programme\opera\program\plugins\ssldivx.dll
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{a33fa729-d155-4b23-842b-2c665ecabdb6}"= "c:\programme\The_Pirate_Bay\tbThe_.dll" [2009-09-08 2260504]
[HKEY_CLASSES_ROOT\clsid\{a33fa729-d155-4b23-842b-2c665ecabdb6}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a33fa729-d155-4b23-842b-2c665ecabdb6}]
2009-09-08 11:32 2260504 ----a-w- c:\programme\The_Pirate_Bay\tbThe_.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{a33fa729-d155-4b23-842b-2c665ecabdb6}"= "c:\programme\The_Pirate_Bay\tbThe_.dll" [2009-09-08 2260504]
[HKEY_CLASSES_ROOT\clsid\{a33fa729-d155-4b23-842b-2c665ecabdb6}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{A33FA729-D155-4B23-842B-2C665ECABDB6}"= "c:\programme\The_Pirate_Bay\tbThe_.dll" [2009-09-08 2260504]
[HKEY_CLASSES_ROOT\clsid\{a33fa729-d155-4b23-842b-2c665ecabdb6}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\programme\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\programme\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-19 266497]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-02-07 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-02-07 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-02-07 118784]
"SunJavaUpdateSched"="c:\programme\Java\jre6\bin\jusched.exe" [2009-09-25 149280]
" Malwarebytes Anti-Malware (reboot)"="c:\programme\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"QuickTime Task"="c:\programme\QuickTime\QTTask.exe" [2009-09-04 417792]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-05-16 2879488]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-06-28 16248320]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programme\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programme\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programme\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [10.09.2009 19:41 64160]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [24.09.2009 22:15 206256]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [12.09.2009 16:04 54752]
R2 MZCCntrl;T-Online WLAN Adapter Steuerungsdienst;c:\programme\Gemeinsame Dateien\Marmiko Shared\MZCCntrl.exe [10.09.2009 17:06 61440]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [26.09.2009 12:33 604416]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\programme\Lavasoft\Ad-Aware\AAWService.exe [18.01.2009 23:34 1028432]
S3 fsssvc;Windows Live Family Safety-Dienst;c:\programme\Windows Live\Family Safety\fsssvc.exe [05.08.2009 22:48 704864]
S3 MACNDIS5;MACNDIS5 NDIS Protocol Driver;c:\progra~1\GEMEIN~1\MARMIK~1\MACNDIS5.SYS [10.09.2009 17:06 17280]
S3 MIINPazX;MIINPazX NDIS Protocol Driver;c:\progra~1\GEMEIN~1\MARMIK~1\MInfraIS\MIINPazX.SYS [10.09.2009 17:06 17152]
S3 MTOnlPktAlyX;MTOnlPktAlyX NDIS Protocol Driver;c:\progra~1\T-Online\T-ONLI~2\BASIS-~1\Basis1\MTOnlPktAlyX.SYS [10.09.2009 17:06 17536]
S3 sdAuxService;PC Tools Auxiliary Service;c:\programme\Spyware Doctor\pctsAuxs.exe [24.09.2009 22:14 348752]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Inhalt des "geplante Tasks" Ordners
2009-09-26 c:\windows\Tasks\1-Klick-Wartung.job
- c:\programme\TuneUp Utilities 2009\OneClickStarter.exe [2009-04-27 12:39]
2009-09-24 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\programme\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 17:42]
2009-09-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programme\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
.
------- Zusätzlicher Suchlauf -------
.
IE: Easy-WebPrint - Drucken - c:\programme\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
IE: Easy-WebPrint - Schnelldruck - c:\programme\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint - Vorschau - c:\programme\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint - Zu Druckliste hinzufügen - c:\programme\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-28 16:46
Windows 5.1.2600 Service Pack 3 NTFS
Scanne versteckte Prozesse...
Scanne versteckte Autostarteinträge...
Scanne versteckte Dateien...
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\WmiApSrv]
"ImagePath"=""
.
Zeit der Fertigstellung: 2009-09-28 16:48
ComboFix-quarantined-files.txt 2009-09-28 14:48
Vor Suchlauf: 20 Verzeichnis(se), 21.515.567.104 Bytes frei
Nach Suchlauf: 21 Verzeichnis(se), 22.089.158.656 Bytes frei
Current=3 Default=3 Failed=0 LastKnownGood=5 Sets=1,2,3,4,5
330 --- E O F --- 2009-09-24 21:19