Vany_Vany | 19.09.2008 16:11 | blacklight und malwarebytes haben nix gefunden hier das combofix log: Code:
ComboFix 08-09-16.05 - Vany 2008-09-19 17:04:20.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1031.18.1170 [GMT 2:00]
ausgeführt von:: C:\Users\Vany\Desktop\ComboFix.exe
* Neuer Wiederherstellungspunkt wurde erstellt
.
((((((((((((((((((((((( Dateien erstellt von 2008-08-19 bis 2008-09-19 ))))))))))))))))))))))))))))))
.
2008-09-19 16:59 . 2008-09-19 16:59 <DIR> d-------- C:\Program Files\CCleaner
2008-09-16 17:40 . <DIR> C:\Windows\Sonic Collab CD Style Uninstaller
2008-09-16 17:40 . 903,680 C:\Windows\Sonic Collab CD Style.scr
2008-09-16 17:40 . 495,104 C:\Windows\Sonic Collab CD Style.exe
2008-09-16 17:40 . 161,078 C:\Windows\Sonic Collab CD Style.bmp
2008-09-16 17:40 . 23,558 C:\Windows\Sonic Collab CD Style.ico
2008-09-16 17:40 . 18,804 C:\Windows\Sonic Collab CD Style.swf
2008-09-16 17:40 . 686 C:\Windows\Sonic Collab CD Style.c3
2008-09-16 17:40 . 686 C:\Windows\Sonic Collab CD Style.c1
2008-09-16 17:40 . 639 C:\Windows\Sonic Collab CD Style.c4
2008-09-16 17:40 . 0 C:\Windows\Sonic Collab CD Style.ini
2008-09-10 20:30 . 2008-07-31 03:13 4,240,384 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-09-10 20:30 . 2008-07-31 05:32 28,160 --a------ C:\Windows\System32\Apphlpdm.dll
2008-09-10 20:27 . 2008-08-02 03:01 625,152 --a------ C:\Windows\System32\drivers\dxgkrnl.sys
2008-09-10 20:27 . 2008-06-26 05:29 565,248 --a------ C:\Windows\System32\emdmgmt.dll
2008-09-10 20:27 . 2008-06-26 05:29 303,616 --a------ C:\Windows\System32\wmpeffects.dll
2008-09-10 20:27 . 2008-05-08 21:21 211,968 --a------ C:\Windows\System32\drivers\mrxsmb10.sys
2008-09-10 20:27 . 2008-05-20 04:07 148,480 --a------ C:\Windows\System32\drivers\nwifi.sys
2008-09-10 20:27 . 2008-06-26 05:29 45,056 --a------ C:\Windows\System32\dataclen.dll
2008-09-10 20:27 . 2008-08-02 05:26 36,864 --a------ C:\Windows\System32\cdd.dll
2008-09-10 16:52 . 2008-09-10 16:52 <DIR> d----c--- C:\Windows\System32\DRVSTORE
2008-09-10 16:52 . 2008-04-17 13:12 107,368 --a------ C:\Windows\System32\GEARAspi.dll
2008-09-10 16:52 . 2008-04-17 13:12 15,464 --a------ C:\Windows\System32\drivers\GEARAspiWDM.sys
2008-09-10 16:51 . 2008-09-10 16:51 <DIR> d-------- C:\Users\All Users\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-09-10 16:51 . 2008-09-10 16:51 <DIR> d-------- C:\ProgramData\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-09-10 16:51 . 2008-09-10 16:51 <DIR> d-------- C:\Program Files\iTunes
2008-09-10 16:51 . 2008-09-10 16:51 <DIR> d-------- C:\Program Files\iPod
2008-09-10 16:48 . 2008-09-10 16:49 <DIR> d-------- C:\Program Files\QuickTime
2008-09-08 19:08 . 2008-09-08 19:08 <DIR> d-------- C:\Users\Vany\AppData\Roaming\JGoodies
2008-09-08 19:08 . 2008-09-08 19:08 <DIR> d-------- C:\Program Files\JGoodies
2008-09-06 15:09 . 2008-09-06 15:09 90,112 --a------ C:\Windows\System32\QuickTimeVR.qtx
2008-09-06 15:09 . 2008-09-06 15:09 57,344 --a------ C:\Windows\System32\QuickTime.qts
2008-09-03 16:27 . 2008-09-03 16:27 <DIR> d-------- C:\Users\All Users\Avira
2008-09-03 16:27 . 2008-09-03 16:27 <DIR> d-------- C:\ProgramData\Avira
2008-09-03 16:27 . 2008-09-03 16:27 <DIR> d-------- C:\Program Files\Avira
2008-09-02 18:32 . 2008-09-02 19:16 <DIR> d-------- C:\Users\Vany\.jenny
2008-08-29 10:18 . 2008-08-29 10:18 87,336 --a------ C:\Windows\System32\dns-sd.exe
2008-08-29 09:53 . 2008-08-29 09:53 61,440 --a------ C:\Windows\System32\dnssd.dll
2008-08-28 19:42 . 2008-08-28 19:42 <DIR> d-------- C:\Users\All Users\Yahoo!
2008-08-28 19:42 . 2008-08-28 19:42 <DIR> d-------- C:\ProgramData\Yahoo!
2008-08-28 19:41 . 2008-08-28 19:41 <DIR> d-------- C:\Users\Vany\AppData\Roaming\Yahoo!
2008-08-28 19:40 . 2008-08-28 19:41 <DIR> d-------- C:\Program Files\Yahoo!
2008-08-26 16:06 . 1999-12-17 10:13 86,016 --a------ C:\Windows\unvise32.exe
2008-08-26 16:04 . 2008-08-26 16:06 <DIR> d-------- C:\Program Files\Parallel Port Joystick
2008-08-23 11:22 . 2007-05-16 16:45 3,497,832 --a------ C:\Windows\system\d3dx9_34.dll
2008-08-23 10:04 . 2008-09-04 22:01 <DIR> d-------- C:\Program Files\Project64 1.6
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-19 12:56 --------- d-----w C:\Users\Vany\AppData\Roaming\VMware
2008-09-19 12:53 --------- d-----w C:\ProgramData\VMware
2008-09-18 20:03 --------- d-----w C:\Users\Vany\AppData\Roaming\mIRC
2008-09-17 19:26 --------- d-----w C:\Users\Vany\AppData\Roaming\LimeWire
2008-09-13 20:19 --------- d-----w C:\Users\Vany\AppData\Roaming\dvdcss
2008-09-10 19:23 --------- d-----w C:\ProgramData\Microsoft Help
2008-09-10 14:49 --------- d-----w C:\Program Files\Bonjour
2008-09-10 14:48 --------- d-----w C:\Program Files\Common Files\Apple
2008-09-02 15:27 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-09-01 22:16 38,528 ----a-w C:\Windows\system32\drivers\mbamswissarmy.sys
2008-09-01 22:16 17,200 ----a-w C:\Windows\system32\drivers\mbam.sys
2008-09-01 15:52 --------- d-----w C:\Users\Vany\AppData\Roaming\ICQ
2008-08-28 12:48 --------- d-----w C:\Program Files\ICQ6
2008-08-20 17:43 --------- d-----w C:\Program Files\Opera
2008-08-20 14:15 --------- d-----w C:\Program Files\mIRC
2008-08-18 12:44 --------- d-----w C:\Program Files\Apple Software Update
2008-08-17 20:51 --------- d-----w C:\Users\Vany\AppData\Roaming\acccore
2008-08-17 20:48 --------- d-----w C:\ProgramData\AOL OCP
2008-08-17 20:48 --------- d-----w C:\ProgramData\AOL
2008-08-17 20:48 --------- d-----w C:\Program Files\AIM6
2008-08-17 20:47 --------- d-----w C:\ProgramData\Viewpoint
2008-08-17 20:47 --------- d-----w C:\Program Files\Viewpoint
2008-08-17 20:45 --------- d-----w C:\Program Files\Common Files\AOL
2008-08-17 15:34 --------- d-----w C:\Program Files\Total Video Converter
2008-08-15 14:02 --------- d-----w C:\Program Files\Windows Mail
2008-08-14 13:16 --------- d-----w C:\Program Files\RegCleaner
2008-08-13 17:17 --------- d-----w C:\Program Files\LimeWire
2008-08-10 13:38 --------- d-----w C:\Program Files\Red Kawa
2008-08-09 10:55 --------- d-----w C:\Program Files\Java
2008-08-09 10:54 --------- d-----w C:\Program Files\Common Files\Java
2008-08-03 19:26 --------- d-----w C:\ProgramData\WindowsSearch
2008-08-03 17:34 --------- d-----w C:\Program Files\Kaspersky Lab
2008-08-03 17:32 --------- d-----w C:\ProgramData\Kaspersky Lab Setup Files
2008-08-03 15:42 42,952 ----a-w C:\Windows\system32\drivers\PktIcpt.sys
2008-08-03 15:37 45,768 ----a-w C:\Windows\system32\drivers\MiniIcpt.sys
2008-08-03 15:36 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-08-03 15:35 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-03 15:30 --------- d-----w C:\ProgramData\McAfee
2008-08-03 13:05 --------- d-----w C:\Users\Vany\AppData\Roaming\Apple Computer
2008-08-03 13:05 --------- d-----w C:\Program Files\Safari
2008-07-31 22:46 --------- d-----w C:\Program Files\SlySoft
2008-07-31 21:05 --------- d-----w C:\Program Files\VMware
2008-07-31 21:05 --------- d-----w C:\Program Files\Common Files\VMware
2008-07-31 03:32 460,288 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-07-31 03:32 2,154,496 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-07-31 03:32 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-07-26 21:05 --------- d-----w C:\Program Files\Frets on Fire
2008-07-26 17:54 --------- d-----w C:\Users\Vany\AppData\Roaming\Audacity
2008-07-26 17:48 --------- d-----w C:\Program Files\CamStudio
2008-07-26 17:31 --------- d-----w C:\Program Files\Audacity 1.3 Beta (Unicode)
2008-07-24 21:43 --------- d-----w C:\Program Files\Xilisoft
2008-07-24 15:35 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-22 21:23 --------- d-----w C:\Program Files\WinTV
2008-07-22 12:33 --------- d-----w C:\Program Files\vtplus
2008-07-22 12:32 --------- d-----w C:\Program Files\Common Files\IviSDK
2008-07-21 17:25 --------- d-----w C:\Program Files\Burn4Free
2008-07-16 01:32 2,048 ----a-w C:\Windows\System32\tzres.dll
2008-07-07 14:10 737,280 ----a-w C:\Windows\iun6002.exe
2008-07-03 19:53 348,160 ----a-w C:\Windows\System32\MSVCR71.dll
2008-06-26 03:29 801,280 ----a-w C:\Windows\System32\NaturalLanguage6.dll
2008-06-26 01:45 2,644,480 ----a-w C:\Windows\System32\NlsLexicons0009.dll
2008-06-26 01:45 12,240,896 ----a-w C:\Windows\System32\NlsLexicons0007.dll
2008-06-21 11:49 830,464 ----a-w C:\Windows\System32\wininet.dll
2008-06-19 03:31 361,984 ----a-w C:\Windows\System32\IPSECSVC.DLL
2008-01-21 02:43 174 --sha-w C:\Program Files\desktop.ini
2007-03-09 07:12 27,648 --sha-w C:\Windows\System32\AVSredirect.dll
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-04-01 486856]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-21 125952]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-06 1029416]
"topi"="C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2007-07-10 581632]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2006-12-06 366400]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-02-22 1836544]
"Desktop SMS"="C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe" [2007-06-18 1507328]
"TPwrMain"="C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE" [2008-01-17 431456]
"SmoothView"="C:\Program Files\Toshiba\SmoothView\SmoothView.exe" [2008-01-25 509816]
"00TCrdMain"="C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe" [2008-01-22 712704]
"Toshiba Registration"="C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe" [2007-05-04 571024]
"BtTray"="C:\Program Files\IVT Corporation\BlueSoleil\BtTray.exe" [2008-07-03 258134]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"EPGServiceTool"="C:\PROGRA~3\WinTV\EPG Services\System\EPGClient.exe" [2008-04-17 688128]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"vmware-tray"="C:\Programme\VMware\VMware Workstation\vmware-tray.exe" [2008-03-03 72240]
"VMware hqtray"="C:\Programme\VMware\VMware Workstation\hqtray.exe" [2008-03-03 55856]
"CloneCDTray"="C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" [2006-09-28 57344]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 413696]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-09-08 289576]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-29 C:\Windows\RtHDVCpl.exe]
"NDSTray.exe"="NDSTray.exe" [BU]
C:\Users\Vany\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - C:\Program Files\Stardock\ObjectDock\ObjectDock.exe [2008-07-16 3581680]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
AutoStart IR.lnk - C:\Programme\WinTV\Ir.exe [2008-07-22 110647]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\vio\dvacm.acm
"msacm.iac2"= C:\PROGRA~1\REPLAY~1\iac25_32.ax
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{96761CEC-CC5E-474F-B4C6-6C83E1E58ED9}"= UDP:C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe:BlueSoleilCS
"{41A9E5B6-338D-4AD9-B182-68BFE7DADD8B}"= TCP:C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe:BlueSoleilCS
"{92B92234-A456-4CEB-B2D0-FBF070BC4446}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{259782D8-AF4C-4ABB-80FF-A6AAB99FED91}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{E3AB54A0-AE49-4C13-9DB3-065A18E702B6}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{D1DEABDF-DBC6-452D-A4B7-B625F7F5B1B9}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{E82E73EF-4409-4B42-A4AB-07468C61A65F}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{BCFF3D46-D1E9-4A11-BF75-C182923DFFF4}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{B71F0269-377B-4B4D-8844-6A88AE64AC6F}C:\\program files\\mirc\\mirc.exe"= UDP:C:\program files\mirc\mirc.exe:mIRC
"UDP Query User{3F456D3F-8FBA-4531-BEEF-57E14500AFC0}C:\\program files\\mirc\\mirc.exe"= TCP:C:\program files\mirc\mirc.exe:mIRC
"TCP Query User{445698B1-F1A4-4C44-9C87-A89AE8E2927C}C:\\program files\\opera\\opera.exe"= UDP:C:\program files\opera\opera.exe:Opera Internet Browser
"UDP Query User{F3D68E03-EEBF-4872-A8F0-5AF2B4B784F6}C:\\program files\\opera\\opera.exe"= TCP:C:\program files\opera\opera.exe:Opera Internet Browser
"TCP Query User{8C26D7F0-A2EA-41D4-BA1C-5C2B20B8CB3C}C:\\program files\\icq6\\icq.exe"= UDP:C:\program files\icq6\icq.exe:ICQ Library
"UDP Query User{6F84683B-9353-49DF-B06C-FF7B79AC68AA}C:\\program files\\icq6\\icq.exe"= TCP:C:\program files\icq6\icq.exe:ICQ Library
"{1115D499-D4FE-4A0B-83A5-A25C774B86F6}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{014A602A-2924-4400-AE27-904502181998}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{05588AA8-3590-465D-9C03-11D9D7E8C5A7}"= UDP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{EC79E865-0A4B-45E0-BEDA-139ADDA3BFD9}"= TCP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{576E9163-9CD2-4C35-85ED-BC05B43FE441}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{4B5441C1-AC90-4DF0-AD8F-100BDFA5E874}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{2B285866-F1E3-4AD5-BAFF-5CE8B8D2FBE2}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{A6159A39-1966-452C-BB3C-7060305716AD}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{95C12656-37A3-4121-BEBA-939414C25E65}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{03CD4F6D-507D-48C7-AB73-018F7E8AB5CA}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{904EB30E-D102-4371-9E5E-C2CBA481E313}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{69F87269-01A9-4797-9AB6-78633B917DC7}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
R0 AtiPcie;ATI PCI Express (3GIO) Filter;C:\Windows\system32\DRIVERS\AtiPcie.sys [2006-10-30 7680]
R2 BlueSoleilCS;BlueSoleilCS;C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe [2008-07-03 1155180]
R2 EPGService;EPGService;C:\PROGRA~3\WinTV\EPG Services\System\EPGService.exe [2008-04-09 436224]
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-07-27 2929664]
R3 BsHelpCS;BsHelpCS;C:\Program Files\IVT Corporation\BlueSoleil\BsHelpCS.exe [2007-08-17 57447]
R3 FwLnk;FwLnk Driver;C:\Windows\system32\DRIVERS\FwLnk.sys [2006-11-20 7168]
R3 PPJoyBus;Parallel Port Joystick Bus device driver;C:\Windows\system32\drivers\PPJoyBus.sys [2003-08-10 11330]
R3 PPortJoystick;Parallel Port Joystick device driver;C:\Windows\system32\drivers\PPortJoy.sys [2003-08-10 21922]
R3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54 MBit/s USB 2.0 Netzwerkadapter;C:\Windows\system32\DRIVERS\RTL8187B.sys [2007-12-26 290304]
S3 ASPI;Advanced SCSI Programming Interface Driver;C:\Windows\System32\DRIVERS\ASPI32.sys [2002-07-17 84832]
S3 HauppaugeTVServer;HauppaugeTVServer;C:\PROGRA~1\WinTV\HCWTVS~1.EXE [2008-03-31 815104]
S3 hcw95bda;Hauppauge MOD7700 Tuner Driver;C:\Windows\system32\Drivers\hcw95bda.sys [2008-04-17 560640]
S3 hcw95rc;Hauppauge MOD7700 IR Driver;C:\Windows\system32\DRIVERS\hcw95rc.sys [2008-04-17 15616]
S3 RTSTOR;Realtek USB 2.0 Card Reader;C:\Windows\system32\drivers\RTSTOR.SYS [2008-02-20 60416]
S4 ConfigFree Service;ConfigFree Service;C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe [2007-12-25 40960]
S4 ErrDev;Microsoft Hardware Error Device Driver;C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe [2005-11-17 1527900]
S4 MegaSR;MegaSR;C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
S4 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [2007-12-03 126976]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5db03cd4-48e5-11dd-8775-00030d000001}]
\shell\AutoRun\command - D:\SETUP.EXE
\shell\configure\command - D:\SETUP.EXE
\shell\install\command - D:\SETUP.EXE
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
WebBrowser-{4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - (no file)
HKCU-Run-TOSCDSPD - TOSCDSPD.EXE
.
------- Zusätzlicher Suchlauf -------
.
FireFox -: Profile - C:\Users\Vany\AppData\Roaming\Mozilla\Firefox\Profiles\d0k8vdlc.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.graphicguestbook.com/vanyvany
FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\npdivx32.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\NPMetaStream3.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\NPOFF12.DLL
FF -: plugin - C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF -: plugin - C:\Program Files\Yahoo!\Shared\npYState.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-19 17:07:30
Windows 6.0.6001 Service Pack 1 NTFS
Scanne versteckte Prozesse...
Scanne versteckte Autostarteinträge...
Scanne versteckte Dateien...
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
**************************************************************************
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
Prozess: C:\Windows\Explorer.exe
-> C:\Windows\system32\BsLangInDepRes.dll
.
Zeit der Fertigstellung: 2008-09-19 17:09:43
ComboFix-quarantined-files.txt 2008-09-19 15:09:13
Vor Suchlauf: 9 Verzeichnis(se), 14,951,051,264 Bytes frei
Nach Suchlauf: 18 Verzeichnis(se), 14,812,254,208 Bytes frei
259 --- E O F --- 2008-09-19 13:00:39 |