| 
 Hier das Combo-Fix Log: 
Combofix Logfile:   Code: 
 ComboFix 10-07-14.02 - Administrator 15.07.2010  15:17:51.5.2 - x86 NETWORKMicrosoft Windows XP Professional  5.1.2600.3.1252.49.1031.18.2046.1800 [GMT 2:00]
 ausgeführt von:: c:\dokumente und einstellungen\Administrator\Desktop\cofi.exe
 .
 
 ((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
 .
 
 c:\windows\system32\ipseccmd.exe
 c:\windows\system32\usrmgr.exe
 
 Infizierte Kopie von c:\windows\system32\drivers\atapi.sys wurde gefunden und desinfiziert
 Kopie von - Kitty had a snack :p wurde wiederhergestellt
 .
 (((((((((((((((((((((((   Dateien erstellt von 2010-06-15 bis 2010-07-15  ))))))))))))))))))))))))))))))
 .
 
 2010-07-13 11:07 . 2010-07-13 11:07        --------        d-----w-        C:\_OTL
 2010-07-13 09:47 . 2010-07-13 09:48        --------        d-----w-        C:\rsit
 2010-07-12 12:18 . 2010-07-13 12:24        664        ----a-w-        c:\windows\system32\d3d9caps.dat
 2010-07-11 14:11 . 2010-07-12 14:29        --------        d-----w-        c:\dokumente und einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\ldtjelamy
 2010-07-01 15:04 . 2010-07-01 15:04        1975408        ----a-w-        c:\dokumente und einstellungen\All Users\Anwendungsdaten\NOS\Adobe_Downloads\GoogleToolbarInstaller_en32_signed.exe
 
 .
 ((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
 .
 2010-07-12 11:41 . 2009-08-20 13:43        --------        d-----w-        c:\programme\Malwarebytes' Anti-Malware
 2010-07-11 15:28 . 2009-06-19 16:03        1100        ----a-w-        c:\windows\system32\d3d8caps.dat
 2010-07-11 14:17 . 2009-08-21 12:57        --------        d-----w-        c:\programme\CCleaner
 2010-07-01 17:07 . 2009-01-13 14:08        --------        d-----w-        c:\dokumente und einstellungen\All Users\Anwendungsdaten\NOS
 2010-07-01 17:06 . 2006-06-28 09:47        --------        d-----w-        c:\programme\Google
 2010-06-27 12:37 . 2006-11-21 18:09        --------        d-----w-        c:\programme\GUILD WARS
 2010-06-22 14:16 . 2010-02-01 15:23        --------        d-----w-        c:\programme\KaloMa
 2010-05-30 10:31 . 2010-05-30 10:31        --------        d-----w-        c:\dokumente und einstellungen\Administrator\Anwendungsdaten\Avira
 2010-05-26 16:01 . 2006-06-28 09:42        --------        d-----w-        c:\programme\XP-AntiSpy
 2010-05-26 10:07 . 2006-07-17 08:28        98304        ----a-w-        c:\windows\system32\CmdLineExt.dll
 2010-05-06 10:31 . 2002-12-31 12:00        916480        ----a-w-        c:\windows\system32\wininet.dll
 2010-05-02 08:05 . 2002-12-31 12:00        1851392        ----a-w-        c:\windows\system32\win32k.sys
 2010-05-01 15:46 . 2008-05-13 09:07        152750        ----a-w-        c:\windows\War3Unin.dat
 2010-04-29 13:39 . 2009-08-20 13:43        38224        ----a-w-        c:\windows\system32\drivers\mbamswissarmy.sys
 2010-04-29 13:39 . 2009-08-20 13:43        20952        ----a-w-        c:\windows\system32\drivers\mbam.sys
 2010-04-20 05:29 . 2002-12-31 12:00        285696        ----a-w-        c:\windows\system32\atmfd.dll
 .
 
 ((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
 .
 .
 *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
 REGEDIT4
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
 "Verknüpfung mit der High Definition Audio-Eigenschaftenseite"="HDAudPropShortcut.exe" [2004-03-17 61952]
 "Samsung Common SM"="c:\windows\Samsung\ComSMMgr\ssmmgr.exe" [2005-07-03 372736]
 "QuickTime Task"="c:\programme\QuickTime\qttask.exe" [2006-06-28 98304]
 "Malwarebytes Anti-Malware (reboot)"="c:\programme\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]
 
 [HKEY_LOCAL_MACHINE\software\microsoft\security center]
 "AntiVirusOverride"=dword:00000001
 
 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
 "EnableFirewall"= 0 (0x0)
 
 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
 "%windir%\\system32\\sessmgr.exe"=
 "c:\\Programme\\NAMCO BANDAI Games\\Warhammer® Mark of Chaos\\Warhammer.exe"=
 "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
 "g:\\Warcraft III\\Warcraft III.exe"=
 "c:\\Programme\\The Creative Assembly\\Rome - Total War\\RomeTW.exe"=
 "c:\\Programme\\WEB.DE\\WEB.DE MultiMessenger\\MESSENGR.EXE"=
 "c:\\Programme\\ICQ6.5\\ICQ.exe"=
 "c:\\Programme\\Garena\\Garena.exe"=
 "c:\\WINDOWS\\system32\\PnkBstrA.exe"=
 "c:\\WINDOWS\\system32\\PnkBstrB.exe"=
 "c:\\Programme\\The Creative Assembly\\Rome - Total War\\RomeTW-BI.exe"=
 "c:\\Dokumente und Einstellungen\\Administrator\\temp\\TeamViewer\\Version5\\TeamViewer.exe"=
 "c:\\Programme\\Skype\\Plugin Manager\\skypePM.exe"=
 "c:\\Programme\\Skype\\Phone\\Skype.exe"=
 "c:\\Programme\\Java\\jre6\\bin\\java.exe"=
 
 S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [21.07.2009 12:21 721904]
 S3 GarenaPEngine;GarenaPEngine;\??\c:\dokume~1\ADMINI~1\LOKALE~1\Temp\YLO5.tmp --> c:\dokume~1\ADMINI~1\LOKALE~1\Temp\YLO5.tmp [?]
 .
 Inhalt des "geplante Tasks" Ordners
 
 2010-07-11 c:\windows\Tasks\OGALogon.job
 - c:\windows\system32\OGAEXEC.exe [2009-08-03 14:07]
 
 2010-07-11 c:\windows\Tasks\User_Feed_Synchronization-{117DDDD8-B5A2-4142-9C91-0696CDDE48BA}.job
 - c:\windows\system32\msfeedssync.exe [2007-08-13 02:31]
 .
 .
 ------- Zusätzlicher Suchlauf -------
 .
 uStart Page = hxxp://www.google.de/
 uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
 uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
 IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 Trusted Zone: kaspersky.com\www
 TCP: {0B316D96-1017-4617-B52A-C617BD9C68B8} = 192.168.100.1
 FF - ProfilePath - c:\dokumente und einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\9oes8frx.default\
 FF - prefs.js: browser.search.selectedEngine - GoogIe
 FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
 FF - prefs.js: keyword.URL - hxxp://www.offos.com/search/?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&rls=8QYAJ5lM&q=
 FF - plugin: c:\programme\Google\Update\1.2.183.7\npGoogleOneClick8.dll
 
 ---- FIREFOX Richtlinien ----
 
 FF - user.js: browser.search.selectedEngine - GoogIe
 FF - user.js: keyword.URL - hxxp://www.offos.com/search/?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&rls=8QYAJ5lM&q=
 FF - user.js: yahoo.homepage.dontask - truec:\programme\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
 c:\programme\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
 c:\programme\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
 c:\programme\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
 c:\programme\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
 c:\programme\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
 c:\programme\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
 c:\programme\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
 c:\programme\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
 c:\programme\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type",                  5);
 c:\programme\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
 c:\programme\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
 c:\programme\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
 c:\programme\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
 c:\programme\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
 c:\programme\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
 c:\programme\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation",  false);
 c:\programme\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
 c:\programme\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
 c:\programme\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
 c:\programme\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
 c:\programme\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
 c:\programme\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
 c:\programme\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
 c:\programme\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
 .
 
 **************************************************************************
 
 catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
 Rootkit scan 2010-07-15 15:21
 Windows 5.1.2600 Service Pack 3 NTFS
 
 Scanne versteckte Prozesse...
 
 Scanne versteckte Autostarteinträge...
 
 Scanne versteckte Dateien...
 
 Scan erfolgreich abgeschlossen
 versteckte Dateien: 0
 
 **************************************************************************
 
 [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]
 "ImagePath"="\??\c:\dokume~1\ADMINI~1\LOKALE~1\Temp\YLO5.tmp"
 .
 --------------------- Gesperrte Registrierungsschluessel ---------------------
 
 [HKEY_USERS\S-1-5-21-746137067-1177238915-725345543-500\Software\Microsoft\Internet Explorer\User Preferences]
 @Denied: (2) (Administrator)
 "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
 d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,af,09,3d,96,18,26,c8,4d,95,4c,14,\
 "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
 d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,af,09,3d,96,18,26,c8,4d,95,4c,14,\
 
 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
 @Denied: (A 2) (Everyone)
 @="FlashBroker"
 "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"
 
 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
 "Enabled"=dword:00000001
 
 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
 @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
 
 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
 @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
 
 [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
 @Denied: (A 2) (Everyone)
 @="IFlashBroker4"
 
 [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
 @="{00020424-0000-0000-C000-000000000046}"
 
 [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
 @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
 "Version"="1.0"
 
 [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•6~*]
 "7040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
 .
 --------------------- Durch laufende Prozesse gestartete DLLs ---------------------
 
 - - - - - - - > 'winlogon.exe'(416)
 c:\windows\system32\Ati2evxx.dll
 .
 Zeit der Fertigstellung: 2010-07-15  15:22:21
 ComboFix-quarantined-files.txt  2010-07-15 13:22
 ComboFix2.txt  2009-08-22 16:05
 
 Vor Suchlauf: 1.684.422.656 Bytes frei
 Nach Suchlauf: 1.648.193.536 Bytes frei
 
 - - End Of File - - DBD47BD379298DCE741F34B0DADEC285
 --- --- ---  |