Code:
ComboFix 09-02-07.01 - Leo 2009-02-08 21:17:21.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1031.18.3070.1557 [GMT 1:00]
ausgeführt von:: c:\users\Leo\Desktop\ComboFix.exe
AV: Norton Internet Security *On-access scanning disabled* (Updated)
FW: Norton Internet Security *disabled*
* Neuer Wiederherstellungspunkt wurde erstellt
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
D:\Autorun.inf
D:\resycled
E:\Autorun.inf
E:\resycled
K:\Autorun.inf
K:\resycled
k:\resycled\boot.com
.
((((((((((((((((((((((( Dateien erstellt von 2009-01-08 bis 2009-02-08 ))))))))))))))))))))))))))))))
.
2009-02-08 21:09 . 2009-02-08 21:09 <DIR> d-------- c:\program files\CCleaner
2009-02-07 22:03 . 2009-02-07 22:03 <DIR> d-------- c:\users\Leo\AppData\Roaming\SUPERAntiSpyware.com
2009-02-07 22:03 . 2009-02-07 22:03 <DIR> d-------- c:\users\All Users\SUPERAntiSpyware.com
2009-02-07 22:03 . 2009-02-07 22:03 <DIR> d-------- c:\programdata\SUPERAntiSpyware.com
2009-02-07 22:03 . 2009-02-07 22:03 <DIR> d-------- c:\program files\SUPERAntiSpyware
2009-02-07 20:32 . 2009-02-07 20:32 <DIR> d-------- c:\users\Leo\AppData\Roaming\Malwarebytes
2009-02-07 20:32 . 2009-02-07 20:32 <DIR> d-------- c:\users\All Users\Malwarebytes
2009-02-07 20:32 . 2009-02-07 20:32 <DIR> d-------- c:\programdata\Malwarebytes
2009-02-07 20:32 . 2009-02-07 20:32 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-07 20:32 . 2009-01-14 16:11 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
2009-02-07 20:32 . 2009-01-14 16:11 15,504 --a------ c:\windows\System32\drivers\mbam.sys
2009-02-07 11:12 . 2009-02-07 11:12 0 --ah----- C:\ntuser.dat.LOG2
2009-02-07 11:12 . 2009-02-07 11:12 0 --ah----- C:\ntuser.dat.LOG1
2009-02-07 11:12 . 2009-02-07 11:12 0 --a------ C:\ntuser.dat
2009-02-07 09:13 . 2009-02-07 09:14 <DIR> d-------- c:\windows\System32\Adobe
2009-02-07 08:48 . 2009-02-07 08:48 <DIR> d-------- c:\program files\MSXML 4.0
2009-02-06 18:33 . 2008-04-26 09:26 891,448 --a------ c:\windows\System32\drivers\tcpip.sys
2009-02-06 17:43 . 2009-02-06 17:43 250 --a------ c:\windows\gmer.ini
2009-02-06 17:14 . 2009-02-08 00:01 <DIR> d-------- c:\program files\Navilog1
2009-02-05 22:48 . 2009-02-05 22:48 <DIR> d-------- c:\program files\Trend Micro
2009-02-05 21:48 . 2009-02-05 21:48 <DIR> d-------- c:\users\Leo\AppData\Roaming\InstallShield
2009-02-04 13:44 . 2009-02-04 13:44 <DIR> d-------- c:\program files\Xvid
2009-02-04 13:44 . 2008-04-27 10:33 765,952 --a------ c:\windows\System32\xvidcore.dll
2009-02-04 13:44 . 2008-04-27 10:35 180,224 --a------ c:\windows\System32\xvidvfw.dll
2009-02-04 13:44 . 2007-06-28 18:55 77,824 --a------ c:\windows\System32\xvid.ax
2009-02-03 17:33 . 2009-02-03 17:33 <DIR> d-------- c:\users\Leo\AppData\Roaming\PeerNetworking
2009-02-01 15:54 . 2009-02-04 10:27 138,184 --a------ c:\windows\System32\drivers\PnkBstrK.sys
2009-02-01 15:54 . 2009-02-01 15:54 66,872 --a------ c:\windows\System32\PnkBstrA.exe
2009-02-01 15:53 . 2009-02-04 10:27 183,112 --a------ c:\windows\System32\PnkBstrB.exe
2009-02-01 15:49 . 2009-02-01 15:49 <DIR> d-------- c:\users\Leo\AppData\Roaming\Leadertech
2009-01-30 18:58 . 2009-01-30 18:59 <DIR> d-------- c:\users\Leo\AppData\Roaming\Autodesk
2009-01-30 18:52 . 2009-02-05 21:47 <DIR> d-------- c:\users\All Users\Autodesk
2009-01-30 18:52 . 2009-02-05 21:47 <DIR> d-------- c:\programdata\Autodesk
2009-01-30 18:52 . 2009-02-05 21:40 <DIR> d-------- c:\program files\Autodesk
2009-01-30 18:37 . 2009-01-30 18:37 <DIR> d-------- C:\Autodesk
2009-01-30 17:59 . 2009-01-30 17:59 <DIR> d-------- c:\program files\MAXON
2009-01-29 19:32 . 2009-01-29 19:32 <DIR> d-------- c:\program files\Veoh Networks
2009-01-29 19:30 . 2009-01-29 19:31 9,708,400 --a------ c:\users\Leo\VeohWebPlayerSetup_eng.exe
2009-01-29 16:12 . 2009-01-29 16:16 <DIR> d-------- c:\users\Leo\AppData\Roaming\ICQ
2009-01-29 16:12 . 2009-01-29 16:12 <DIR> d-------- c:\users\All Users\ICQ
2009-01-29 16:12 . 2009-01-29 16:12 <DIR> d-------- c:\programdata\ICQ
2009-01-29 16:12 . 2009-01-29 16:12 <DIR> d-------- c:\program files\ICQ6Toolbar
2009-01-29 16:11 . 2009-01-29 16:16 <DIR> d-------- c:\program files\ICQ6.5
2009-01-29 16:10 . 2009-01-29 16:10 16,242,136 --a------ c:\users\Leo\install_pro7_icq65.exe
2009-01-28 20:34 . 2009-01-28 20:34 <DIR> d-------- c:\users\All Users\Google
2009-01-28 19:27 . 2009-01-28 19:27 <DIR> d-------- c:\program files\Google
2009-01-28 19:24 . 2009-01-28 19:25 34,031,720 --a------ c:\users\Leo\GoogleSketchUpWEN.exe
2009-01-28 18:51 . 2009-01-28 18:51 <DIR> d-------- c:\users\Leo\AppData\Roaming\Blender Foundation
2009-01-28 18:51 . 2009-01-28 18:51 <DIR> d-------- c:\program files\Blender Foundation
2009-01-28 18:50 . 2009-01-28 18:51 9,903,535 --a------ c:\users\Leo\blender-2.48a-windows.exe
2009-01-25 18:23 . 2009-01-25 20:10 <DIR> d-------- c:\program files\Bethesda Softworks
2009-01-24 20:49 . 2009-01-24 21:26 <DIR> d-------- c:\users\Leo\AppData\Roaming\DivX
2009-01-24 20:48 . 2009-01-24 20:48 <DIR> d-------- c:\program files\DivX
2009-01-24 20:48 . 2009-01-24 20:48 <DIR> d-------- c:\program files\Common Files\PX Storage Engine
2009-01-24 20:39 . 2009-01-24 20:39 <DIR> d-------- c:\program files\AVIcodec
2009-01-21 17:11 . 2009-01-21 17:11 <DIR> d-------- c:\users\Leo\AppData\Roaming\OpenOffice.org
2009-01-21 17:10 . 2009-01-21 17:10 <DIR> d-------- c:\program files\OpenOffice.org 3
2009-01-13 22:22 . 2009-01-19 16:25 <DIR> d-------- c:\users\Leo\AppData\Roaming\HPAppData
2009-01-13 19:48 . 2009-01-13 19:48 <DIR> d-------- C:\DRIVERS
2009-01-13 18:24 . 2009-02-08 00:04 12 --a------ c:\windows\bthservsdp.dat
2009-01-12 20:04 . 2009-01-12 20:04 <DIR> d-------- c:\users\Leo\DSphpBB2.2
2009-01-10 21:01 . 2009-01-11 17:53 <DIR> d-------- c:\users\All Users\FLEXnet
2009-01-10 21:01 . 2009-01-11 17:53 <DIR> d-------- c:\programdata\FLEXnet
2009-01-10 20:55 . 2009-01-10 20:55 <DIR> d-------- c:\program files\Common Files\Macrovision Shared
2009-01-10 19:20 . 2009-01-10 19:20 <DIR> d-------- c:\users\All Users\WEBREG
2009-01-10 19:20 . 2009-01-10 19:20 <DIR> d-------- c:\programdata\WEBREG
2009-01-10 19:12 . 2009-01-10 19:14 <DIR> d-------- c:\users\Leo\AppData\Roaming\HP
2009-01-10 19:08 . 2009-01-10 18:43 186,529 --------- c:\windows\hpoins21.dat.temp
2009-01-10 19:08 . 2008-02-13 10:18 7,262 --------- c:\windows\hpomdl21.dat.temp
2009-01-10 18:50 . 2009-01-10 18:50 0 --ah----- c:\windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-01-10 18:38 . 2009-01-10 18:38 <DIR> d-------- c:\users\All Users\HP Product Assistant
2009-01-10 18:38 . 2009-01-10 18:38 <DIR> d-------- c:\programdata\HP Product Assistant
2009-01-10 18:37 . 2009-01-10 18:37 <DIR> d-------- c:\program files\Common Files\Hewlett-Packard
2009-01-10 18:36 . 2007-12-07 00:55 271,704 --a------ c:\windows\System32\hpzids01.dll
2009-01-10 18:36 . 2007-03-15 15:32 118,272 --a------ c:\windows\System32\hpz3l5ha.dll
2009-01-10 18:35 . 2007-11-01 12:28 970,752 --a------ c:\windows\System32\hpotiop5.dll
2009-01-10 18:35 . 2007-11-01 12:28 729,088 --a------ c:\windows\System32\hpowiax5.dll
2009-01-10 18:35 . 2007-11-01 12:28 364,544 --a------ c:\windows\System32\hppldcoi.dll
2009-01-10 18:35 . 2007-11-01 12:28 309,760 --a------ c:\windows\System32\difxapi.dll
2009-01-10 18:35 . 2007-11-01 12:28 303,104 --a------ c:\windows\System32\hpovst12.dll
2009-01-10 18:11 . 2009-01-10 19:14 186,113 --a------ c:\windows\hpoins21.dat
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-08 16:16 --------- d-----w c:\programdata\Symantec
2009-02-07 21:02 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-02-07 16:32 86,016 ----a-w c:\windows\System32\OpenAL32.dll
2009-02-07 16:32 409,600 ----a-w c:\windows\System32\wrap_oal.dll
2009-02-07 10:43 --------- d-----w c:\users\Leo\AppData\Roaming\Azureus
2009-02-07 09:16 --------- d-----w c:\program files\Windows Mail
2009-02-06 12:59 --------- d-----w c:\program files\Norton Internet Security
2009-02-06 12:59 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-02-06 12:45 806 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-02-06 12:45 124,464 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-02-06 12:45 10,635 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-02-06 12:45 --------- d-----w c:\program files\Symantec
2009-02-05 21:04 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-05 20:28 --------- d-----w c:\program files\Spore
2009-01-27 05:08 --------- d-----w c:\program files\Vuze
2009-01-25 21:13 --------- d-----w c:\program files\Microsoft Games for Windows - LIVE
2009-01-25 19:45 --------- d-----w c:\programdata\NVIDIA
2009-01-25 19:41 --------- d-----w c:\program files\AGEIA Technologies
2009-01-10 19:58 --------- d-----w c:\program files\Common Files\Adobe
2009-01-10 18:13 --------- d-----w c:\programdata\HP
2009-01-10 17:49 --------- d-----w c:\programdata\Hewlett-Packard
2009-01-07 10:28 453,152 ----a-w c:\windows\System32\nvuninst.exe
2009-01-04 21:10 --------- d-----w c:\program files\Cheat Engine
2009-01-01 19:25 107,888 ----a-w c:\windows\System32\CmdLineExt.dll
2009-01-01 18:33 174 --sha-w c:\program files\desktop.ini
2009-01-01 18:24 --------- d-----w c:\program files\Windows Sidebar
2009-01-01 18:24 --------- d-----w c:\program files\Windows Photo Gallery
2009-01-01 18:24 --------- d-----w c:\program files\Windows Journal
2009-01-01 18:24 --------- d-----w c:\program files\Windows Defender
2009-01-01 18:24 --------- d-----w c:\program files\Windows Collaboration
2009-01-01 18:24 --------- d-----w c:\program files\Windows Calendar
2009-01-01 17:54 82,432 ----a-w c:\windows\System32\axaltocm.dll
2009-01-01 17:54 101,888 ----a-w c:\windows\System32\ifxcardm.dll
2009-01-01 17:28 --------- d-----w c:\program files\Microsoft Silverlight
2008-12-31 12:03 --------- d---a-w c:\programdata\TEMP
2008-12-31 12:03 --------- d-----w c:\program files\Fraps
2008-12-30 13:36 --------- d-----w c:\program files\SEGA
2008-12-30 11:34 --------- d-----w c:\program files\OpenAL
2008-12-30 11:32 --------- d-----w c:\program files\Infinity
2008-12-19 23:30 81,920 ----a-w c:\windows\System32\frapsvid.dll
2008-12-19 21:47 --------- d-----w c:\programdata\maxdome
2008-12-19 20:44 --------- d-----w c:\program files\maxdome
2008-12-19 20:34 --------- d-----w c:\users\Leo\AppData\Roaming\CyberLink
2008-12-19 20:34 --------- d-----w c:\programdata\CyberLink
2008-12-18 18:25 --------- d-----w c:\programdata\Microsoft Help
2008-12-18 18:25 --------- d-----w c:\program files\MSBuild
2008-12-18 18:25 --------- d-----w c:\program files\Microsoft Works
2008-12-16 02:42 288,768 ----a-w c:\windows\system32\drivers\srv.sys
2008-12-13 18:43 --------- d-----w c:\users\Leo\AppData\Roaming\Ubisoft
2008-12-13 18:43 --------- d-----w c:\programdata\Ubisoft
2008-12-12 22:35 269,312 ----a-w c:\windows\System32\es.dll
2008-12-12 22:30 --------- d-----w c:\program files\7-Zip
2008-12-12 21:59 --------- d-----w c:\program files\UltraISO
2008-12-12 21:59 --------- d-----w c:\program files\Common Files\EZB Systems
2008-12-12 21:35 --------- d-----w c:\program files\MagicDisc
2008-12-12 16:36 --------- d-----w c:\programdata\Azureus
2008-12-11 00:33 86,016 ----a-w c:\windows\System32\dpl100.dll
2008-12-11 00:33 200,704 ----a-w c:\windows\System32\dtu100.dll
2008-12-10 08:45 70,936 ----a-w c:\windows\System32\PhysXLoader.dll
2008-12-09 20:59 94,720 ----a-w c:\windows\System32\PortableDeviceClassExtension.dll
2008-12-09 20:59 61,440 ----a-w c:\windows\System32\winipsec.dll
2008-12-09 20:59 361,984 ----a-w c:\windows\System32\IPSECSVC.DLL
2008-12-09 20:59 28,672 ----a-w c:\windows\System32\FwRemoteSvr.dll
2008-12-09 20:59 272,896 ----a-w c:\windows\System32\polstore.dll
2008-12-09 20:59 241,152 ----a-w c:\windows\System32\PortableDeviceApi.dll
2008-12-09 20:59 160,768 ----a-w c:\windows\System32\PortableDeviceTypes.dll
2008-12-09 20:57 428,544 ----a-w c:\windows\System32\EncDec.dll
2008-12-09 20:57 296,960 ----a-w c:\windows\System32\gdi32.dll
2008-12-09 20:57 293,376 ----a-w c:\windows\System32\psisdecd.dll
2008-12-09 20:56 541,696 ----a-w c:\windows\AppPatch\AcLayers.dll
2008-12-09 20:56 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll
2008-12-09 20:56 460,288 ----a-w c:\windows\AppPatch\AcSpecfc.dll
2008-12-09 20:56 4,240,384 ----a-w c:\windows\System32\GameUXLegacyGDFs.dll
2008-12-09 20:56 28,672 ----a-w c:\windows\System32\Apphlpdm.dll
2008-12-09 20:56 212,480 ----a-w c:\windows\system32\drivers\mrxsmb10.sys
2008-12-09 20:56 2,560 ----a-w c:\windows\AppPatch\AcRes.dll
2008-12-09 20:56 2,154,496 ----a-w c:\windows\AppPatch\AcGenral.dll
2008-12-09 20:56 173,056 ----a-w c:\windows\AppPatch\AcXtrnal.dll
2008-12-09 20:56 1,695,744 ----a-w c:\windows\System32\gameux.dll
2008-12-09 20:55 303,616 ----a-w c:\windows\System32\wmpeffects.dll
2008-12-09 20:55 2,032,640 ----a-w c:\windows\System32\win32k.sys
2008-12-09 20:54 2,048 ----a-w c:\windows\System32\tzres.dll
2008-12-09 20:54 2,048 ----a-w c:\windows\System32\msxml3r.dll
2008-12-09 20:54 1,191,936 ----a-w c:\windows\System32\msxml3.dll
2008-12-09 20:52 2,927,104 ----a-w c:\windows\explorer.exe
2008-12-09 20:51 827,392 ----a-w c:\windows\System32\wininet.dll
2008-12-09 20:48 9,847,296 ----a-w c:\windows\System32\NlsData000a.dll
2008-12-09 20:47 988,216 ----a-w c:\windows\System32\winload.exe
2008-12-09 20:47 927,288 ----a-w c:\windows\System32\winresume.exe
2008-12-09 20:47 615,992 ----a-w c:\windows\System32\ci.dll
2008-12-09 20:47 6,656 ----a-w c:\windows\System32\kbd106n.dll
2008-12-09 20:47 46,592 ----a-w c:\windows\System32\setbcdlocale.dll
2008-12-09 20:47 40,960 ----a-w c:\windows\System32\srclient.dll
2008-12-09 20:47 378,368 ----a-w c:\windows\System32\srcore.dll
2008-12-09 20:47 318,464 ----a-w c:\windows\System32\rstrui.exe
2008-12-09 20:47 19,000 ----a-w c:\windows\System32\kd1394.dll
2008-12-09 20:47 14,848 ----a-w c:\windows\System32\srdelayed.exe
2008-12-09 20:46 712,704 ----a-w c:\windows\System32\WindowsCodecs.dll
2008-12-09 20:46 443,392 ----a-w c:\windows\System32\win32spl.dll
2008-12-09 20:46 425,472 ----a-w c:\windows\System32\PhotoMetadataHandler.dll
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"HPAdvisor"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2007-10-03 1783136]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2008-12-16 3528440]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-01-15 1830128]
"WindowsWelcomeCenter"="oobefldr.dll" [2008-01-19 c:\windows\System32\oobefldr.dll]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"SunJavaUpdateReg"="c:\windows\system32\jureg.exe" [2007-04-07 54936]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-15 13683232]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-01-15 92704]
"RtHDVCpl"="RtHDVCpl.exe" [2007-10-25 c:\windows\RtHDVCpl.exe]
c:\users\Leo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2008-12-12 575488]
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-09-12 384000]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 11:05 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3codecp"= l3codecp.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{4722D3EB-754A-494A-9301-86394D434B61}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"TCP Query User{0E5D303F-34C2-4C42-9100-5B9AD1CD5C07}c:\\program files\\vuze\\azureus.exe"= UDP:c:\program files\vuze\azureus.exe:Azureus
"UDP Query User{72553F42-E27D-4CB6-AAC1-32E4D36F1EB5}c:\\program files\\vuze\\azureus.exe"= TCP:c:\program files\vuze\azureus.exe:Azureus
"TCP Query User{1F6D858C-2648-4258-AA7F-AA37D7573464}c:\\program files\\vuze\\azureus.exe"= UDP:c:\program files\vuze\azureus.exe:Azureus
"UDP Query User{AB9F25F0-A463-4ACD-A66C-8107CF08AD88}c:\\program files\\vuze\\azureus.exe"= TCP:c:\program files\vuze\azureus.exe:Azureus
"{BE362805-5A2F-4342-8297-5986A50A72FE}"= Disabled:UDP:f:\setup\HPZNUI01.EXE:hpznui01.exe
"{8A04E8EC-9A2A-410D-8266-D656F64D01D4}"= Disabled:TCP:f:\setup\HPZNUI01.EXE:hpznui01.exe
"{CEA31D7D-86BE-4A9D-A9E3-2A88976A8A2A}"= UDP:5353:Adobe CSI CS4
"{E450F57E-899B-40AF-B518-94CB2C43CF7D}"= UDP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{B3CE741B-030B-43D7-805A-EB4BA3B96BBC}"= TCP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"TCP Query User{1B98AF67-E721-4667-9975-C28F8B5EC8FF}c:\\program files\\icq6.5\\icq.exe"= UDP:c:\program files\icq6.5\icq.exe:ICQ Library
"UDP Query User{6E9D065C-06E5-4B1B-B116-50E9CE5F0479}c:\\program files\\icq6.5\\icq.exe"= TCP:c:\program files\icq6.5\icq.exe:ICQ Library
"{36F0735C-ED5A-44AC-BBF1-2A469A5E949F}"= UDP:c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:Veoh Web Player
"{2844E1DD-A176-46C4-A5C2-C51B95898D3C}"= TCP:c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:Veoh Web Player
"{1ACCEEC3-16E9-4307-B673-66A24C80BAC9}"= UDP:c:\program files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe:Rockstar Games Social Club
"{FFFCCE5D-9CE2-4B32-9CE2-0E17230EFA56}"= TCP:c:\program files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe:Rockstar Games Social Club
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\ipsdefs\20090129.001\IDSvix86.sys [2009-02-06 270384]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2009-01-15 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2009-01-15 55024]
R2 HPBtnSrv;HP Chasis Button Service;c:\hp\HPEZBTN\HPBtnSrv.exe [2008-01-23 198240]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [2009-01-29 222456]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [2007-08-24 149352]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-02-06 99376]
R3 HCW85BDA;Hauppauge WinTV 885 Video Capture;c:\windows\System32\drivers\HCW85BDA.sys [2008-01-23 1129344]
R3 netr73;USB Wireless 802.11 b/g Adaptor Driver for Vista;c:\windows\System32\drivers\netr73.sys [2008-02-26 493568]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-01-15 7408]
R3 SYMNDISV;SYMNDISV;c:\windows\System32\drivers\symndisv.sys [2008-06-13 41008]
S3 COH_Mon;COH_Mon;c:\windows\System32\drivers\COH_Mon.sys [2007-05-29 23888]
--- Andere Dienste/Treiber im Speicher ---
*NewlyCreated* - COMHOST
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K]
\shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL k:\resycled\boot.com h:
\shell\Open\command - k:\resycled\boot.com h:
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{724bc243-eabe-11dd-9736-001e8cb6840b}]
\shell\AutoRun\command - N:\WDSetup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f1be7e67-c5fd-11dd-879c-001e8cb6840b}]
\shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL k:\resycled\boot.com h:
\shell\Open\command - k:\resycled\boot.com h:
.
Inhalt des "geplante Tasks" Ordners
2009-02-06 c:\windows\Tasks\Norton Internet Security - Systemprüfung ausführen - Leo.job
- c:\program files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2007-08-26 12:19]
2009-02-08 c:\windows\Tasks\User_Feed_Synchronization-{2E4BA3E0-E5DE-49DC-877A-FB76915FC9A1}.job
- c:\windows\system32\msfeedssync.exe [2008-01-19 08:33]
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
HKLM-Run-HP Health Check Scheduler - [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://start.icq.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=81&bd=Pavilion&pf=desktop
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Leo\AppData\Roaming\Mozilla\Firefox\Profiles\e9b75n57.default\
FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)
FF - prefs.js: browser.startup.homepage - google.com
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-08 21:20:45
Windows 6.0.6001 Service Pack 1 NTFS
Scanne versteckte Prozesse...
Scanne versteckte Autostarteinträge...
Scanne versteckte Dateien...
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
**************************************************************************
.
Zeit der Fertigstellung: 2009-02-08 21:22:33
ComboFix-quarantined-files.txt 2009-02-08 20:22:31
Vor Suchlauf: 20 Verzeichnis(se), 563.487.424.512 Bytes frei
Nach Suchlauf: 20 Verzeichnis(se), 563,469,950,976 Bytes frei
338 --- E O F --- 2009-02-07 07:52:27 |