Also hab das gemacht: Code:
ComboFix 09-12-25.05 - Johannes 26.12.2009 21:58:28.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.49.1031.18.2047.902 [GMT 1:00]
ausgeführt von:: c:\users\Johannes\Desktop\cofi.exe
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows-Defender *enabled* (Outdated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
. ADS - Windows: deleted 24 bytes in 1 streams.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-3556998658-2275902154-2085766584-1001
c:\$recycle.bin\S-1-5-21-3556998658-2275902154-2085766584-1002
c:\$recycle.bin\S-1-5-21-3556998658-2275902154-2085766584-500
C:\install.exe
c:\users\Johannes\AppData\Roaming\inst.exe
c:\users\Johannes\x.exe
c:\windows\system32\reboot.txt
.
((((((((((((((((((((((( Dateien erstellt von 2009-11-26 bis 2009-12-26 ))))))))))))))))))))))))))))))
.
2009-12-26 21:08 . 2009-12-26 21:08 -------- d-----w- c:\users\Johannes\AppData\Local\temp
2009-12-26 21:08 . 2009-12-26 21:08 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-12-26 17:59 . 2009-12-26 18:00 -------- d-----w- c:\users\Johannes\AppData\Local\Divinity 2
2009-12-26 17:52 . 2009-12-26 17:52 -------- d-----w- c:\programdata\Divinity 2
2009-12-24 12:50 . 2009-12-24 12:50 -------- d-----w- c:\users\Johannes\AppData\Roaming\Malwarebytes
2009-12-24 12:50 . 2009-12-03 15:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-24 12:50 . 2009-12-24 12:50 -------- d-----w- c:\programdata\Malwarebytes
2009-12-24 12:50 . 2009-12-03 15:13 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-24 12:43 . 2009-12-24 12:43 -------- d-----w- C:\rsit
2009-12-24 12:08 . 2009-12-24 12:08 -------- d-----w- c:\users\Johannes\AppData\Roaming\TrojanHunter
2009-12-23 17:52 . 2009-12-23 17:52 -------- d-----w- c:\program files\Trend Micro
2009-12-23 13:02 . 2009-12-23 13:34 -------- d-----w- c:\program files\Crazy Island
2009-12-17 16:12 . 2009-12-17 16:14 -------- d-----w- c:\users\Johannes\AppData\Local\IM
2009-12-17 16:12 . 2009-12-17 16:13 -------- d-----w- c:\programdata\IM
2009-12-17 16:12 . 2009-12-17 16:12 -------- d-----w- c:\programdata\IncrediMail
2009-12-16 15:49 . 2009-12-16 15:49 164880 ---ha-w- c:\users\Johannes\AppData\Roaming\Microsoft\Virtual PC\VPCKeyboard.dll
2009-12-08 16:51 . 2009-12-08 16:51 323584 ----a-w- c:\users\Johannes\AppData\Roaming\TVU networks\TVU AutoUpgrade\TVUPlayer2.4.9.1.exe
2009-12-07 13:46 . 2009-12-07 13:46 -------- d-----w- c:\program files\Microsoft
2009-12-07 13:44 . 2008-02-22 04:47 53248 ----a-w- c:\windows\system32\davclnt.dll
2009-12-06 09:26 . 2009-12-06 09:26 -------- d-----w- c:\programdata\Firefly Studios
2009-12-04 16:11 . 2009-03-09 14:27 453456 ----a-w- c:\windows\system32\d3dx10_41.dll
2009-12-04 16:11 . 2009-03-09 14:27 1846632 ----a-w- c:\windows\system32\D3DCompiler_41.dll
2009-12-04 16:11 . 2009-03-16 13:18 235352 ----a-w- c:\windows\system32\xactengine3_4.dll
2009-12-04 16:11 . 2008-10-15 05:22 452440 ----a-w- c:\windows\system32\d3dx10_40.dll
2009-12-04 16:11 . 2008-10-15 05:22 2036576 ----a-w- c:\windows\system32\D3DCompiler_40.dll
2009-12-04 16:11 . 2008-10-15 05:22 4379984 ----a-w- c:\windows\system32\D3DX9_40.dll
2009-12-04 16:11 . 2008-07-10 10:01 467984 ----a-w- c:\windows\system32\d3dx10_39.dll
2009-12-04 16:11 . 2008-07-10 10:00 1493528 ----a-w- c:\windows\system32\D3DCompiler_39.dll
2009-12-04 16:11 . 2008-05-30 13:18 238088 ----a-w- c:\windows\system32\xactengine3_1.dll
2009-12-04 15:28 . 2009-12-04 15:29 -------- d-----w- c:\program files\NVIDIA Corporation
2009-12-04 15:27 . 2009-11-21 02:34 76392 ----a-w- c:\windows\system32\OpenCL.dll
2009-12-04 15:27 . 2009-11-21 02:34 4241000 ----a-w- c:\windows\system32\nvwgf2um.dll
2009-12-04 15:27 . 2009-11-21 02:34 11515752 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2009-12-04 15:26 . 2009-11-21 02:34 4001384 ----a-w- c:\windows\system32\nvcuda.dll
2009-12-04 15:26 . 2009-11-21 02:34 2243176 ----a-w- c:\windows\system32\nvcuvid.dll
2009-12-04 15:26 . 2009-11-21 02:34 1989224 ----a-w- c:\windows\system32\nvcuvenc.dll
2009-12-04 15:26 . 2009-11-21 02:34 14064232 ----a-w- c:\windows\system32\nvoglv32.dll
2009-12-04 15:26 . 2009-11-21 02:34 182888 ----a-w- c:\windows\system32\nvcod178.dll
2009-12-04 15:26 . 2009-11-21 02:34 182888 ----a-w- c:\windows\system32\nvcod.dll
2009-12-04 15:26 . 2009-11-21 02:34 11381352 ----a-w- c:\windows\system32\nvcompiler.dll
2009-12-04 15:15 . 2009-09-04 16:44 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2009-12-04 15:15 . 2009-09-04 16:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2009-12-04 15:15 . 2009-09-04 16:44 238936 ----a-w- c:\windows\system32\xactengine3_5.dll
2009-12-04 15:15 . 2009-09-04 16:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2009-12-04 15:15 . 2009-09-04 16:29 235344 ----a-w- c:\windows\system32\d3dx11_42.dll
2009-12-04 15:15 . 2009-09-04 16:29 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll
2009-12-04 15:15 . 2009-09-04 16:29 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2009-12-04 15:15 . 2009-09-04 16:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2009-12-04 15:15 . 2008-07-31 09:41 68616 ----a-w- c:\windows\system32\XAPOFX1_1.dll
2009-12-04 15:15 . 2008-07-31 09:40 509448 ----a-w- c:\windows\system32\XAudio2_2.dll
2009-12-04 15:15 . 2008-07-31 09:41 238088 ----a-w- c:\windows\system32\xactengine3_2.dll
2009-12-04 15:07 . 2009-12-04 15:07 -------- d-----w- c:\program files\SystemRequirementsLab
2009-12-04 15:01 . 2009-12-11 16:26 -------- d-----w- c:\users\Johannes\AppData\Roaming\Tropico 3
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-26 20:56 . 2008-11-02 10:03 -------- d-----w- c:\programdata\NVIDIA
2009-12-26 20:56 . 2008-12-24 10:39 352614 ---ha-w- c:\windows\system32\drivers\vsconfig.xml
2009-12-26 20:51 . 2009-12-04 15:32 35180 ----a-w- c:\programdata\nvModes.dat
2009-12-26 20:40 . 2009-07-26 19:08 -------- d-----w- c:\users\Johannes\AppData\Roaming\vlc
2009-12-26 17:57 . 2008-11-02 09:55 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-12-26 17:57 . 2008-04-22 13:48 -------- d-----w- c:\program files\AGEIA Technologies
2009-12-26 15:55 . 2009-04-26 08:36 8792072 ----a-w- c:\windows\Internet Logs\tvDebug.zip
2009-12-26 12:30 . 2009-12-26 12:30 29576698 ----a-w- c:\windows\Internet Logs\vsmon_on_demand_2009_12_26_12_44_15_full.dmp.zip
2009-12-26 11:44 . 2009-12-26 12:25 2765312 ----a-w- c:\windows\Internet Logs\xDB7BC3.tmp
2009-12-25 20:16 . 2008-12-25 11:21 -------- d-----w- c:\programdata\Google Updater
2009-12-25 13:51 . 2007-06-16 00:22 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-25 13:34 . 2006-11-02 15:33 909836 ----a-w- c:\windows\system32\perfc007.dat
2009-12-25 13:34 . 2006-11-02 15:33 3080742 ----a-w- c:\windows\system32\perfh007.dat
2009-12-25 13:20 . 2008-01-04 09:29 271360 ----a-w- c:\windows\system32\drivers\atksgt.sys
2009-12-23 13:59 . 2009-06-28 17:35 -------- d-----w- c:\program files\Vuze
2009-12-23 12:34 . 2009-06-28 17:35 -------- d-----w- c:\users\Johannes\AppData\Roaming\Azureus
2009-12-17 16:14 . 2007-10-12 15:40 127672 ----a-w- c:\users\Johannes\AppData\Local\GDIPFONTCACHEV1.DAT
2009-12-17 14:51 . 2009-04-20 13:25 -------- d-----w- c:\program files\Microsoft Silverlight
2009-12-14 12:07 . 2009-07-30 10:02 4141117 ----a-w- c:\users\Johannes\AppData\Roaming\Azureus\plugins\vuzexcode\mediainfo.exe
2009-12-14 12:07 . 2009-07-30 10:02 6516755 ----a-w- c:\users\Johannes\AppData\Roaming\Azureus\plugins\vuzexcode\ffmpeg.exe
2009-12-12 06:15 . 2009-06-19 11:39 47360 ----a-w- c:\users\Johannes\AppData\Roaming\pcouffin.sys
2009-12-12 06:15 . 2009-06-19 11:39 47360 ----a-w- c:\users\Johannes\AppData\Roaming\pcouffin.sys
2009-12-12 06:15 . 2009-06-19 11:39 -------- d-----w- c:\users\Johannes\AppData\Roaming\Vso
2009-12-12 06:03 . 2007-06-16 00:27 -------- d-----w- c:\programdata\Microsoft Help
2009-12-12 06:02 . 2007-06-16 00:30 -------- d-----w- c:\program files\Microsoft Works
2009-12-11 21:32 . 2008-12-23 12:22 -------- d-----w- c:\program files\Common Files\Steam
2009-12-11 21:25 . 2009-06-27 11:22 -------- d-----w- c:\users\Johannes\AppData\Roaming\My Games
2009-12-08 10:30 . 2009-11-03 12:20 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-12-04 16:03 . 2009-11-17 15:20 -------- d-----w- c:\program files\Kalypso
2009-12-02 09:42 . 2009-01-01 13:08 -------- d-----w- c:\users\Johannes\AppData\Roaming\gtk-2.0
2009-11-21 02:34 . 2009-12-04 15:27 10920 ----a-w- c:\windows\system32\drivers\nvBridge.kmd
2009-11-21 02:34 . 2009-03-27 22:03 592488 ----a-w- c:\windows\system32\nvudisp.exe
2009-11-21 02:34 . 2008-10-07 12:33 9333352 ----a-w- c:\windows\system32\nvd3dum.dll
2009-11-21 02:34 . 2008-10-07 12:33 1249896 ----a-w- c:\windows\system32\nvapi.dll
2009-11-20 19:33 . 2009-11-20 19:33 812648 ----a-w- c:\windows\system32\nvsvc.dll
2009-11-20 19:33 . 2009-11-20 19:33 66664 ----a-w- c:\windows\system32\nvshext.dll
2009-11-20 19:33 . 2009-11-20 19:33 1323624 ----a-w- c:\windows\system32\nvsvcr.dll
2009-11-20 19:33 . 2009-11-20 19:33 12685928 ----a-w- c:\windows\system32\nvcpl.dll
2009-11-20 19:33 . 2009-11-20 19:33 122984 ----a-w- c:\windows\system32\nvvsvc.exe
2009-11-20 19:33 . 2009-11-20 19:33 110184 ----a-w- c:\windows\system32\nvmctray.dll
2009-11-19 20:42 . 2007-07-12 00:13 592488 ----a-w- c:\windows\system32\nvuninst.exe
2009-11-08 12:24 . 2009-11-08 12:24 32863551 ----a-w- c:\windows\Internet Logs\vsmon_on_demand_2009_11_08_12_40_30_full.dmp.zip
2009-11-07 09:30 . 2009-06-17 15:18 -------- d-----w- c:\program files\Opera
2009-11-06 21:44 . 2009-11-06 21:44 -------- d-----w- c:\programdata\EA Logs
2009-11-06 21:41 . 2009-08-12 18:07 -------- d-----w- c:\program files\Common Files\Borland Shared
2009-11-03 16:54 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-11-03 12:20 . 2009-11-03 12:20 -------- d-----w- c:\programdata\Avira
2009-11-03 12:20 . 2009-11-03 12:20 -------- d-----w- c:\program files\Avira
2009-10-29 15:47 . 2009-10-29 15:45 58941696 ----a-w- c:\programdata\Electronic Arts\EADM\cache\{ }\Manager%2010%20Update%201.exe
2009-10-16 14:50 . 2009-11-10 20:13 2520888 ----a-w- c:\users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1t2x47sr.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
2009-10-14 19:51 . 2009-10-15 08:10 2578944 ----a-w- c:\windows\Internet Logs\xDB88CF.tmp
2009-10-14 19:51 . 2009-10-15 08:10 2861056 ----a-w- c:\windows\Internet Logs\xDB85F1.tmp
2009-10-01 08:29 . 2009-11-03 16:02 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-09-29 13:19 . 2009-09-29 13:19 79144 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.1.8\SetupAdmin.exe
2008-05-16 15:04 . 2008-05-16 15:04 24 --sh--w- c:\windows\S0285CC33.tmp
2006-05-03 09:06 . 2009-06-21 17:13 163328 --sh--r- c:\windows\System32\flvDX.dll
2007-02-21 10:47 . 2009-06-21 17:13 31232 --sh--r- c:\windows\System32\msfDX.dll
2008-03-16 12:30 . 2009-06-21 17:13 216064 --sh--r- c:\windows\System32\nbDX.dll
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-18 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-25 39408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-18 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-02-15 4390912]
"Acer Empowering Technology Monitor"="c:\acer\Empowering Technology\SysMonitor.exe" [2007-01-24 319488]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-03-03 959976]
"TerraTec Remote Control"="c:\program files\Common Files\TerraTec\Remote\TTTvRc.exe" [2008-12-09 1105920]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^hpoddt01.exe.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\hpoddt01.exe.lnk
backup=c:\windows\pss\hpoddt01.exe.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer Tour Reminder]
2007-02-15 16:39 151552 ----a-w- c:\acer\AcerTour\Reminder.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-02-27 16:10 35696 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Anti-Blaxx Manager]
2005-05-18 14:08 208896 ----a-w- d:\program files\Anti-Blaxx\Anti-Blaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
2009-03-02 12:08 209153 ----a-w- c:\program files\Avira\AntiVir Desktop\avgnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CamserviceDP]
2007-08-10 13:23 81920 ----a-w- c:\program files\Hercules\DualPix Exchange\CamService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Comrade.exe]
2007-05-27 01:19 36864 ----a-w- c:\program files\GameSpy\Comrade\Comrade.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-04-23 13:51 691656 ----a-w- c:\program files\DAEMON Tools Lite\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eDataSecurity Loader]
2007-02-06 22:04 464168 ----a-w- c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-09-21 14:36 305440 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2009-11-20 19:33 12685928 ----a-w- c:\windows\System32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ProfilerU]
2007-10-02 09:10 233472 ----a-w- c:\program files\Saitek\SD6\Software\ProfilerU.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-04 23:54 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
2009-07-29 15:25 26112 ----a-w- c:\program files\Real\RealPlayer\realplay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SaiMfd]
2007-10-02 09:10 131072 ----a-w- c:\program files\Saitek\SD6\Software\SaiMfd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2008-01-18 22:33 1233920 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\snpstd]
2005-10-11 19:54 339968 ----a-w- c:\windows\vsnpstd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2008-12-25 11:21 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\THGuard]
2009-11-26 14:50 1069728 ----a-w- d:\program files\TrojanHunter 5.2\THGuard.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrayServer]
2008-01-17 17:43 90112 ----a-w- c:\program files\MAGIX\Movies_on_DVD_TV_Edition\Trayserver.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WarReg_PopUp]
2006-11-05 19:48 57344 ----a-w- c:\acer\WR_PopUp\WarReg_PopUp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SafensoftIPS]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
R1 SSHDRV52;SSHDRV52;c:\windows\System32\drivers\SSHDRV52.sys [18.03.2008 09:27 29184]
R2 acedrv11;acedrv11;c:\windows\System32\drivers\ACEDRV11.sys [23.01.2008 09:19 501560]
R2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [03.11.2009 13:20 108289]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [20.11.2009 19:17 240232]
R3 avmaura;AVM USB-Fernanschluss;c:\windows\System32\drivers\avmaura.sys [19.02.2009 19:38 101248]
R3 MODRC;Cinergy DT USB XS Diversity (MKII) IR Service;c:\windows\System32\drivers\modrc.sys [14.03.2009 13:00 13824]
R3 RTL85n86;Realtek 8180/8185 Extensible 802.11-Drahtlosgerätetreiber;c:\windows\System32\drivers\RTL85n86.sys [02.11.2006 11:25 311808]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\System32\drivers\SiSGB6.sys [16.06.2007 09:54 46592]
S0 sptd;sptd;c:\windows\System32\drivers\sptd.sys [20.06.2009 07:40 721904]
S2 gupdate1c9950110ac6966;Google Update Service (gupdate1c9950110ac6966);c:\program files\Google\Update\GoogleUpdate.exe [22.02.2009 16:20 133104]
S3 AVMUNET;AVM FRITZ!Box;c:\windows\System32\drivers\avmunet.sys [01.11.2008 14:03 14976]
S3 camfilt2;camfilt2;c:\windows\System32\drivers\camfilt2.sys [07.02.2009 11:10 94208]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\MAGIX\Common\Database\bin\fbserver.exe [14.03.2009 13:08 1527900]
S3 SiS6350;SiS6350;c:\windows\System32\drivers\SISGRKMD.sys [16.06.2007 09:54 447864]
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://mystart.incredimail.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://de.intl.acer.yahoo.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://de.rd.yahoo.com/customize/ycomp/defaults/su/*http://de.yahoo.com
IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1t2x47sr.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1434207&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1441.4352\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: c:\users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1t2x47sr.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
FF - plugin: d:\program files\VideoLAN\VLC\npvlc.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-eRecoveryService - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-26 22:08
Windows 6.0.6001 Service Pack 1 NTFS
Scanne versteckte Prozesse...
Scanne versteckte Autostarteinträge...
Scanne versteckte Dateien...
c:\users\Johannes\AppData\Local\Temp\catchme.dll 53248 bytes executable
Scan erfolgreich abgeschlossen
versteckte Dateien: 1
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll >>UNKNOWN [0x8589A258]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0x8830e322
\Driver\ACPI -> acpi.sys @ 0x87e95d4c
\Driver\atapi -> 0x8589a258
IoDeviceObjectType ->\Device\Harddisk0\DR0 ->Warning: possible MBR rootkit infection !
user & kernel MBR OK
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
[HKEY_USERS\S-1-5-21-3556998658-2275902154-2085766584-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:29,a1,a9,65,5e,21,e2,56,23,8f,7f,6e,00,2d,37,da,ae,52,ae,3a,2e,6e,44,
d1,16,42,fb,27,d5,e2,4d,87,b1,93,48,44,9b,4f,a7,52,05,48,0d,83,ee,11,99,3e,\
"??"=hex:03,19,76,33,70,8c,2e,19,d1,71,a8,71,bc,15,cf,05
[HKEY_USERS\S-1-5-21-3556998658-2275902154-2085766584-1000\Software\SecuROM\License information*]
"datasecu"=hex:ef,86,f3,4b,61,cb,01,19,2f,95,a2,bf,0e,71,0e,8d,b8,64,f8,be,63,
f0,2a,02,87,e6,22,f8,d0,6c,cb,87,09,0b,cc,bd,d4,3d,0b,cf,e5,49,8c,7f,a5,e6,\
"rkeysecu"=hex:c7,fb,e4,ce,93,66,76,e0,47,ce,f1,93,00,6d,f9,0b
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{4dbda07d-913f-4395-95bd-b316a5c0da0e}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:1400040e
"Dhcpv6State"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{5aab230d-6bb7-4e4f-aab6-f2d4f6da3974}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:0900064f
"Dhcpv6State"=dword:00000000
"Dhcpv6InterfaceOptions"=hex:02,00,00,00,00,00,00,00,0e,00,00,00,00,00,00,00,
ff,ff,ff,7f,00,01,00,01,0f,34,10,fd,00,06,4f,56,03,90,00,00,17,00,00,00,00,\
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{800b7079-e824-4553-8051-d645ab2a060d}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:1600040e
"Dhcpv6State"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{918d182b-f2c0-4cd9-9115-302bcf237123}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:17000000
"Dhcpv6State"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{9c642153-bfe0-4511-a0b6-e778ddd5ea9e}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:07001422
"Dhcpv6State"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{b7e1aa7c-9be4-48e0-a683-a94a698c7e60}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:0800e106
"Dhcpv6State"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{f50c0996-5b4a-4c6a-a322-6e991d4caa0e}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:06001422
"Dhcpv6State"=dword:00000000
.
Zeit der Fertigstellung: 2009-12-26 22:10:39
ComboFix-quarantined-files.txt 2009-12-26 21:10
Vor Suchlauf: 22 Verzeichnis(se), 59.159.400.448 Bytes frei
Nach Suchlauf: 24 Verzeichnis(se), 59.132.710.912 Bytes frei
- - End Of File - - AEFBF348E02938F3AEB7FCA76EFFB9BD
Wasn Kauderwelsch ;)
EDIT: Oh das mit dem SP2 hab ich gar nicht gemerkt...Ich dachte wenn ich ab und zu alle vorgeschlagenen Updates mache nimmt der das mit dazu....
Am Ende von der Sache hier lad ichs mir gleich runter... |