Code:
ComboFix 10-09-28.03 - Zandy 29.09.2010 16:27:41.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.49.1031.18.3070.1963 [GMT 2:00]
ausgeführt von:: c:\users\Zandy\Desktop\ComboFix.exe
FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
SP: Windows-Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\WinPCap
C:\start
c:\users\Zandy\AppData\Roaming\Aqdizi
c:\users\Zandy\AppData\Roaming\Aqdizi\ezoq.muu
c:\users\Zandy\AppData\Roaming\Desktopicon
c:\users\Zandy\AppData\Roaming\Desktopicon\eBay.ico
c:\users\Zandy\AppData\Roaming\Desktopicon\uninst.exe
Infizierte Kopie von c:\windows\system32\drivers\netbt.sys wurde gefunden und desinfiziert
Kopie von - Kitty had a snack :p wurde wiederhergestellt
.
((((((((((((((((((((((( Dateien erstellt von 2010-08-28 bis 2010-09-29 ))))))))))))))))))))))))))))))
.
2010-09-29 14:39 . 2010-09-29 14:40 -------- d-----w- c:\users\Zandy\AppData\Local\temp
2010-09-29 12:53 . 2010-09-29 12:53 -------- d-----w- c:\program files\Logitech Touch Mouse Server
2010-09-28 19:42 . 2010-09-28 19:42 -------- d-----w- C:\_OTL
2010-09-28 13:42 . 2010-09-28 13:48 -------- d-----w- c:\users\Zandy\AppData\Roaming\FreeScreenToVideo
2010-09-28 13:42 . 2010-09-28 13:42 -------- d-----w- c:\program files\Free Screen To Video
2010-09-27 11:59 . 2010-04-29 10:19 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-27 11:59 . 2010-09-27 11:59 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-27 11:59 . 2010-04-29 10:19 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-25 15:33 . 2010-09-25 15:33 -------- d-----w- c:\program files\Orbitdownloader
2010-09-23 13:10 . 2010-09-25 11:59 -------- d-----w- c:\program files\Duplicate Music Files Finder
2010-09-20 13:02 . 2010-09-20 13:02 -------- d-----w- c:\program files\iPod
2010-09-20 13:02 . 2010-09-20 13:03 -------- d-----w- c:\program files\iTunes
2010-09-20 13:00 . 2010-09-20 13:00 -------- d-----w- c:\program files\Apple Software Update
2010-09-20 13:00 . 2010-09-20 13:00 -------- d-----w- c:\program files\Bonjour
2010-09-18 16:25 . 2010-09-18 16:25 -------- d-----w- c:\users\Zandy\AppData\Roaming\ProgSense
2010-09-17 21:27 . 2010-09-17 21:43 -------- d-----w- c:\programdata\FLEXnet
2010-09-17 21:20 . 2010-09-17 21:20 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2010-09-17 19:25 . 2010-09-17 19:25 -------- d-----w- c:\users\Zandy\AppData\Roaming\Download Manager
2010-09-17 15:05 . 2010-09-17 15:05 -------- d-----w- c:\users\Zandy\Deskto
2010-09-17 06:35 . 2010-09-16 15:20 28048 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{ED9EEC5D-C01E-4A04-8570-8884A14C9265}\mpasdlta.vdm
2010-09-17 06:35 . 2010-09-17 06:35 12300688 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{ED9EEC5D-C01E-4A04-8570-8884A14C9265}\mpasbase.vdm
2010-09-16 12:58 . 2010-09-16 12:58 -------- d-----w- c:\programdata\Ableton
2010-09-16 12:58 . 2010-09-16 12:58 -------- d-----w- c:\users\Zandy\AppData\Roaming\Ableton
2010-09-07 13:52 . 2010-09-25 14:57 -------- d-----w- c:\users\Zandy\AppData\Roaming\Notepad++
2010-09-07 13:52 . 2010-09-25 14:57 -------- d-----w- c:\program files\Notepad++
2010-09-02 18:42 . 2010-09-02 18:43 -------- d-----w- c:\program files\QuickTime
2010-09-01 07:12 . 2010-09-01 07:12 73000 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 10.0.0.68\SetupAdmin.exe
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-29 14:33 . 2006-11-02 15:33 656262 ----a-w- c:\windows\system32\perfh007.dat
2010-09-29 14:33 . 2006-11-02 15:33 121228 ----a-w- c:\windows\system32\perfc007.dat
2010-09-29 14:24 . 2010-02-16 15:35 12 ----a-w- c:\windows\bthservsdp.dat
2010-09-29 14:18 . 2008-09-20 17:02 -------- d-----w- c:\users\Zandy\AppData\Roaming\Skype
2010-09-29 14:18 . 2008-09-20 17:07 -------- d-----w- c:\users\Zandy\AppData\Roaming\skypePM
2010-09-29 13:11 . 2009-03-07 16:18 -------- d-----w- c:\users\Zandy\AppData\Roaming\Orbit
2010-09-28 13:57 . 2009-09-06 08:31 183112 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-09-25 15:16 . 2007-11-30 12:49 111616 ----a-w- c:\users\Zandy\AppData\Local\GDIPFONTCACHEV1.DAT
2010-09-25 14:59 . 2009-09-26 21:56 -------- d-----w- c:\program files\TeamViewer
2010-09-25 14:57 . 2008-12-14 11:29 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2010-09-25 14:28 . 2008-01-02 16:42 8052 ----a-w- c:\users\Zandy\AppData\Local\d3d9caps.dat
2010-09-25 11:52 . 2009-11-30 14:33 -------- d-----w- c:\program files\trend micro
2010-09-24 21:14 . 2010-03-03 20:48 0 ----a-w- c:\windows\system32\Access.dat
2010-09-24 15:05 . 2010-04-12 13:08 -------- d-----w- c:\program files\JDownloader
2010-09-21 19:16 . 2010-04-15 15:45 -------- d-sh--r- c:\users\Zandy\AppData\Roaming\dx10ac
2010-09-20 13:02 . 2009-01-30 21:42 -------- d-----w- c:\program files\Common Files\Apple
2010-09-17 21:24 . 2007-05-23 12:24 -------- d-----w- c:\program files\Common Files\Adobe
2010-09-17 21:06 . 2010-04-01 19:48 -------- d-----w- c:\program files\Ask.com
2010-09-14 18:21 . 2010-07-08 15:04 -------- d-----w- c:\users\Zandy\AppData\Roaming\PhotoScape
2010-09-14 14:41 . 2007-12-01 21:15 582544 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\Backup\mpasdlta.vdm
2010-09-13 15:08 . 2009-02-05 13:57 -------- d-----w- c:\programdata\ArcSoft
2010-09-13 15:08 . 2007-05-23 11:06 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-09-13 15:07 . 2009-02-06 14:16 2564863 ----a-w- c:\programdata\ArcSoft\Global Deploy\CheckUpdate\ArcConnect.exe
2010-09-11 19:23 . 2007-11-30 14:50 -------- d-----w- c:\users\Zandy\AppData\Roaming\dvdcss
2010-09-06 17:56 . 2008-02-17 09:00 -------- d-----w- c:\users\Zandy\AppData\Roaming\StarOffice8
2010-09-04 12:19 . 2009-09-06 08:31 138184 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-08-30 20:19 . 2007-05-23 11:09 -------- d-----w- c:\program files\Roxio
2010-08-28 16:20 . 2009-02-05 13:57 -------- d-----w- c:\program files\ArcSoft
2010-08-28 16:19 . 2009-07-13 15:31 -------- d-----w- c:\program files\ElcomSoft
2010-08-28 16:19 . 2008-09-20 17:01 -------- d-----r- c:\program files\Skype
2010-08-28 16:17 . 2010-06-17 20:30 -------- d-----w- c:\program files\thriXXX
2010-08-27 13:57 . 2007-05-23 11:09 -------- d-----w- c:\programdata\Roxio
2010-08-24 18:44 . 2010-05-11 16:15 -------- d-sh--w- c:\users\Zandy\AppData\Roaming\lowsec
2010-08-24 13:00 . 2007-12-01 21:15 12120464 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\Backup\mpasbase.vdm
2010-08-05 21:05 . 2009-03-03 20:42 -------- d-----w- c:\program files\Messenger Plus! Live
2010-07-27 16:44 . 2010-07-27 16:44 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-07-27 16:44 . 2010-07-27 16:44 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-07-11 17:38 . 2010-04-24 20:00 57344 ----a-w- c:\programdata\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-07-11 17:38 . 2010-07-11 17:38 56765 ----a-w- c:\programdata\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-07-11 17:38 . 2010-07-11 17:38 57715 ----a-w- c:\programdata\DivX\Player\Uninstaller.exe
2010-07-11 17:38 . 2010-07-11 17:38 54153 ----a-w- c:\programdata\DivX\DFXPlugin\Uninstaller.exe
2010-07-11 17:22 . 2010-04-24 20:03 895256 ----a-w- c:\programdata\DivX\Setup\DivXSetup.exe
2010-07-11 17:22 . 2010-04-24 20:03 1062184 ----a-w- c:\programdata\DivX\Setup\Resource.dll
.
------- Sigcheck -------
[-] 2010-03-30 . 1171B07E27991296D379472B12174349 . 245248 . . [6.0.6000.16386] . . c:\windows\System32\shsvcs.dll
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-05-26 13:23 1385864 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883840]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-05-13 26192168]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-01 4390912]
"spc1030"="c:\windows\vspc1030.exe" [2008-02-22 684032]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-06-03 1144104]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-07-13 47904]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2010-06-17 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-06-01 2039240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-08-10 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-01 421160]
c:\users\Zandy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech Touch Mouse Server.lnk - c:\program files\Logitech Touch Mouse Server\iTouch-Server-Win.exe [2009-10-23 228352]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Sitecom USB Wireless LAN Utility.lnk - c:\program files\Sitecom Europe BV\Sitecom WL-113 Utility\SiteComUSB.exe [2009-1-19 3477504]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\guard32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer9"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ehTray.exe"=c:\windows\ehome\ehTray.exe
"ICQ"="c:\program files\ICQ6.5\ICQ.exe" silent
"Skype"="c:\program files\Skype\Phone\Skype.exe" /nosplash /minimized
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
"{68657190-7121-20E8-42E7-B6B473543351}"=c:\users\Zandy\AppData\Roaming\Exyfx\abems.exe
"userinit"=c:\users\Zandy\AppData\Roaming\sdra64.exe
"Windows Update"=c:\users\Zandy\AppData\Roaming\netssh.exe
"{433CD6D5-15A6-14F8-9AAC-3730B91D3876}"=c:\users\Zandy\AppData\Roaming\netssh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"VX1000"=c:\windows\vVX1000.exe
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe"
"spc1030"=c:\windows\vspc1030.exe
"StartCCC"=c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
"RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe"
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
"NvSvc"=RUNDLL32.EXE c:\windows\system32\nvsvc.dll,nvsvcStart
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"PlayMovie"="d:\bearbeitungsprogramme\PlayMovie\PMVService.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
"ArcSoft Connection Service"=c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"d-x10c"=c:\users\Zandy\AppData\Roaming\dx10ac\d-xdiag10c.exe
"SwitchBoard"=c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
"AppleSyncNotifier"=c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2780370485-2775809281-2979314199-1000]
"EnableNotifications"=dword:00000001
"EnableNotificationsRef"=dword:00000002
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2009-09-20 133104]
R3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\System32\DRIVERS\ASPI32.sys [2002-07-17 84832]
R3 libusb0;LibUsb-Win32 - Kernel Driver 11/20/2005, 20051120;c:\windows\system32\DRIVERS\libusb0.sys [2006-05-31 29184]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2010-06-17 3890920]
R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 UPnPService;UPnPService;c:\program files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe [2006-12-14 544768]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2010-01-01 691696]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2010-06-04 224240]
S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2010-06-01 30112]
S2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};d:\bearbeitungsprogramme\PlayMovie\000.fcl [2008-05-16 61424]
S3 MicNgBas;Cinergy 2400i DT Base Driver;c:\windows\system32\drivers\MicNgBas.sys [2006-02-11 48768]
S3 MicNgCap;Cinergy 2400i DT Capture Driver;c:\windows\system32\drivers\MicNgCap.sys [2006-02-11 50560]
S3 MicNgTun;Cinergy 2400i DT Tuner Driver;c:\windows\system32\drivers\MicNgTun.sys [2006-02-11 122752]
S3 phaudlwr;Philips Audio Filter;c:\windows\system32\DRIVERS\phaudlwr.sys [2008-05-07 88704]
S3 SPC1030;USB2.0 PC Camera (SPC1030);c:\windows\system32\DRIVERS\spc1030.sys [2008-06-11 3035776]
S3 ZD1211U(Sitecom);Sitecom Wireless Network USB Adapter Driver(Sitecom);c:\windows\system32\DRIVERS\zd1211u.sys [2004-07-05 233472]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
Inhalt des "geplante Tasks" Ordners
2010-09-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-20 19:19]
2010-09-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-20 19:19]
2010-08-31 c:\windows\Tasks\RCHubTask 0 0 {2E6E3A14-F6F5-404E-AC33-87F20083074D} 2145340416~30026154.job
- c:\program files\Common Files\Roxio Shared\9.0\Roxio Central33\Main\Roxio_Central33.exe [2007-02-13 16:51]
2010-09-29 c:\windows\Tasks\User_Feed_Synchronization-{BB2AC692-2CD6-4C68-9DFC-5B9F61E87B2F}.job
- c:\windows\system32\msfeedssync.exe [2006-11-02 09:45]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.google.de/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://de.intl.acer.yahoo.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://go.1und1.de/suchbox/1und1suche?su=%s
IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
IE: Free YouTube Download - c:\users\Zandy\AppData\Roaming\DVDVideoSoftIEHelpers\youtubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\users\Zandy\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm
TCP: {38C40A29-A3EC-4951-93B1-95FA03AA6BE0} = 192.168.178.1,192.168.178.2
TCP: {5B175FDC-3A19-4105-AE85-EF088487102C} = 192.168.182.1,192.168.182.2
TCP: {9CE15D25-E061-4EA7-A67B-2FBB0BF7B106} = 192.168.182.1,192.168.182.2
TCP: {D08FD11B-68BB-4DB9-B05C-0694FD0A3F17} = 192.168.182.1,192.168.182.2
FF - ProfilePath - c:\users\Zandy\AppData\Roaming\Mozilla\Firefox\Profiles\ffmk5zx8.default\
FF - prefs.js: browser.startup.homepage - google.de
FF - component: c:\program files\Orbitdownloader\addons\OneClickYouTubeDownloader\components\GrabXpcom.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX Richtlinien ----
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
MSConfigStartUp-BMIMZMHMFM - c:\users\Zandy\AppData\Local\Temp\Rcx.exe
MSConfigStartUp-LosAlamos - c:\windows\system32\sshnas21.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2010-09-29 16:39
Windows 6.0.6000 NTFS
Scanne versteckte Prozesse...
Scanne versteckte Autostarteinträge...
Scanne versteckte Dateien...
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
"ImagePath"="\??\d:\bearbeitungsprogramme\PlayMovie\000.fcl"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
[HKEY_USERS\S-1-5-21-2780370485-2775809281-2979314199-1000\Software\SecuROM\License information*]
"datasecu"=hex:7e,e8,20,01,50,99,dc,33,e0,d7,a3,74,96,6b,73,2f,63,e9,c8,ba,12,
f3,94,9a,85,38,7f,1e,00,c7,e6,a2,97,c4,5b,8c,b4,73,e9,1d,2b,65,19,a6,f9,6a,\
"rkeysecu"=hex:9b,5a,b7,02,6e,ed,18,d4,57,55,ba,a0,1e,c9,49,72
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
- - - - - - - > 'winlogon.exe'(836)
c:\windows\System32\guard32.dll
- - - - - - - > 'lsass.exe'(680)
c:\windows\system32\guard32.dll
.
Zeit der Fertigstellung: 2010-09-29 16:45:18
ComboFix-quarantined-files.txt 2010-09-29 14:45
Vor Suchlauf: 14 Verzeichnis(se), 56.898.908.160 Bytes frei
Nach Suchlauf: 18 Verzeichnis(se), 56.724.508.672 Bytes frei
- - End Of File - - FCFE09711B073FE17FA14EB365969841 :D gab kleine anlaufschwierigkeiten aber am ende liefs wunderbar ;) |