Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Ad-Aware blockt Win32.Backdoor.Bifrose - Besteht gefahr? (https://www.trojaner-board.de/97092-ad-aware-blockt-win32-backdoor-bifrose-besteht-gefahr.html)

el_ukas 03.04.2011 16:23

Ad-Aware blockt Win32.Backdoor.Bifrose - Besteht gefahr?
 
Hallo,

ich hoffe ich bin hier richtig. Habe bei Suche einen Eintrag gefunden aber konnte dort nicht posten.

Problem: Ich habe Winamp und Airfoil deinstalliert und Ad-Aware hat den Win32.Backdoor.Bifrose geblockt und folgende Log-Datei ausgespuckt.
Frage: Ist mein Pc befallen und muss ich ihn formatieren oder ist er sauber oder kann man den Befall beheben?

Ich danke euch vielmalst im Vorraus.

Ad-Aware-Log:
MSG [2840] 2010/09/06 19:51:02: C:\dokume~1\user\lokale~1\temp\nsl12b.tmp\ns12c.tmp (diagnosis: Malware family: Win32.Backdoor.Bifrose) => Block
MSG [1212] 2010/09/06 19:51:03: C:\dokume~1\user\lokale~1\temp\nsl12b.tmp\ns12d.tmp (diagnosis: Malware family: Win32.Backdoor.Bifrose) => Block
MSG [1056] 2011/04/03 15:36:29: C:\dokume~1\lukefi~1\lokale~1\temp\nsk5d.tmp\ns5e.tmp (diagnosis: Malware family: Win32.Backdoor.Bifrose) => Block
MSG [1976] 2011/04/03 15:36:29: C:\dokume~1\lukefi~1\lokale~1\temp\nsk5d.tmp\ns5f.tmp (diagnosis: Malware family: Win32.Backdoor.Bifrose) => Block
MSG [1164] 2011/04/03 15:56:23: C:\dokume~1\user\lokale~1\temp\nsc3.tmp\ns4.tmp (diagnosis: Malware family: Win32.Backdoor.Bifrose) => Block
MSG [3104] 2011/04/03 15:56:24: C:\dokume~1\user\lokale~1\temp\nsc3.tmp\ns5.tmp (diagnosis: Malware family: Win32.Backdoor.Bifrose) => Block
Ende

[Edit: Diese Ordner (C:\dokume~1\user\lokale~1\temp\nsc3) existieren jedoch nicht!]

Hier das Malware-Log:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Datenbank Version: 6255

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

03.04.2011 17:12:14
mbam-log-2011-04-03 (17-12-14).txt

Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 168140
Laufzeit: 9 Minute(n), 41 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)



Hier das Hijack-Log:
HiJackthis Logfile:
Code:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:41:16, on 03.04.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\Avira\AntiVir Desktop\sched.exe
C:\Programme\Avira\AntiVir Desktop\avguard.exe
C:\Programme\Bonjour\mDNSResponder.exe
C:\Programme\Prevx\prevx.exe
C:\Programme\LogMeIn Hamachi\hamachi-2.exe
C:\Programme\Java\jre6\bin\jqs.exe
C:\Programme\Avira\AntiVir Desktop\avshadow.exe
C:\Programme\McAfee\SiteAdvisor\McSACore.exe
C:\Programme\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Programme\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexingService.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Programme\Synaptics\SynTP\SynTPEnh.exe
C:\Programme\FSC\TouchPad HotKey Utility\TouchPad_HotKey.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Programme\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\sistray.exe
C:\Programme\FSC\Wireless Utility\WirelessSelector.exe
C:\Programme\TuneUp Utilities 2009\OneClick.exe
C:\Programme\TuneUp Utilities 2009\RegistryCleaner.exe
C:\WINDOWS\System32\TuneUpDefragService.exe
C:\Programme\Malwarebytes' Anti-Malware\mbam.exe
L:\Downloads\Sicherheit\HiJackThis204.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = hxxp://www.kaspersky.com/de/heimanwender_deinstallation?kavprod=PersonalPro&build=5.0.383&version=5.0
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: QFX Software KeyScrambler - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Programme\KeyScrambler\KeyScramblerIE.dll
O2 - BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: PDF-XChange Viewer IE-Plugin - {C5D07EB6-BBCE-4DAE-ACBB-D13A8D28CB1F} - C:\Programme\Tracker Software\PDF-XChange Viewer\pdf-viewer\PDFXCviewIEPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre6\bin\jp2ssv.dll
O2 - BHO: kikin Plugin - {E601996F-E400-41CA-804B-CD6373A7EEE2} - (no file)
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: Gutscheinmieze - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - Gutscheinmieze\toolbar.dll (file missing)
O4 - HKLM\..\Run: [SynTPEnh] C:\Programme\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TouchPadHotKey] C:\Programme\FSC\TouchPad HotKey Utility\TouchPad_HotKey.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [avgnt] "C:\Programme\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-21-746137067-1645522239-1177238915-1005\..\Run: [QuickTime Task] "C:\Programme\QuickTime\QTTask.exe" -atboottime (User 'Luke Firewalker')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O4 - Global Startup: WirelessSelector.lnk = ?
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: My kikin - {0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Programme\KeyScrambler\KeyScramblerIE.dll
O9 - Extra 'Tools' menuitem: &KeyScrambler... - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Programme\KeyScrambler\KeyScramblerIE.dll
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Avira AntiVir Planer (AntiVirSchedulerService) - Avira GmbH - C:\Programme\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Programme\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Dienst "Bonjour" (Bonjour Service) - Apple Inc. - C:\Programme\Bonjour\mDNSResponder.exe
O23 - Service: Cherry Device Interface - Cherry, Auerbach Germany, www.cherry.de - C:\Programme\Cherry\CDI\cdi.exe
O23 - Service: CSIScanner - Prevx - C:\Programme\Prevx\prevx.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programme\Gemeinsame Dateien\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Programme\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programme\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Programme\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Programme\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Programme\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexingService.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Programme\CDBurnerXP\NMSAccessU.exe
O23 - Service: TuneUp Drive Defrag-Dienst (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe

--
End of file - 8173 bytes

--- --- ---


Hier das gmer-log:
GMER Logfile:
Code:

GMER 1.0.15.14966 - hxxp://www.gmer.net
Rootkit scan 2011-04-03 17:17:40
Windows 5.1.2600 Service Pack 3


---- System - GMER 1.0.15 ----

SSDT            BA72F2F6                                                                                                              ZwCreateKey
SSDT            BA72F2EC                                                                                                              ZwCreateThread
SSDT            BA72F2FB                                                                                                              ZwDeleteKey
SSDT            BA72F305                                                                                                              ZwDeleteValueKey
SSDT            spyv.sys                                                                                                              ZwEnumerateKey [0xB9EC6CA2]
SSDT            spyv.sys                                                                                                              ZwEnumerateValueKey [0xB9EC7030]
SSDT            BA72F30A                                                                                                              ZwLoadKey
SSDT            spyv.sys                                                                                                              ZwOpenKey [0xB9EA80C0]
SSDT            BA72F2D8                                                                                                              ZwOpenProcess
SSDT            BA72F2DD                                                                                                              ZwOpenThread
SSDT            spyv.sys                                                                                                              ZwQueryKey [0xB9EC7108]
SSDT            spyv.sys                                                                                                              ZwQueryValueKey [0xB9EC6F88]
SSDT            BA72F314                                                                                                              ZwReplaceKey
SSDT            BA72F30F                                                                                                              ZwRestoreKey
SSDT            BA72F300                                                                                                              ZwSetValueKey
SSDT            pxsec.sys (Prevx Realtime Analysis/Prevx)                                                                            ZwTerminateProcess [0xBA10A680]

INT 0x62        ?                                                                                                                    89D70BF8
INT 0x63        ?                                                                                                                    89B99BF8
INT 0x73        ?                                                                                                                    89D70BF8
INT 0x94        ?                                                                                                                    89B99BF8
INT 0xA4        ?                                                                                                                    89B99BF8
INT 0xB1        ?                                                                                                                    89D72F00

---- Kernel code sections - GMER 1.0.15 ----

?              spyv.sys                                                                                                              Das System kann die angegebene Datei nicht finden. !
.text          USBPORT.SYS!DllUnload                                                                                                B9B048AC 5 Bytes  JMP 89B991D8
.text          ahnbxon5.SYS                                                                                                          B9A08386 35 Bytes  [00, 00, 00, 00, 00, 00, 20, ...]
.text          ahnbxon5.SYS                                                                                                          B9A083AA 24 Bytes  [00, 00, 00, 00, 00, 00, 00, ...]
.text          ahnbxon5.SYS                                                                                                          B9A083C4 3 Bytes  [00, 70, 02] {ADD [EAX+0x2], DH}
.text          ahnbxon5.SYS                                                                                                          B9A083C9 1 Byte  [2E]
.text          ahnbxon5.SYS                                                                                                          B9A083C9 11 Bytes  [2E, 00, 00, 00, 5C, 02, 00, ...] {ADD CS:[EAX], AL; ADD [EDX+EAX+0x0], BL; ADD [EAX], AL; ADD [EAX], AL}
.text          ...                                                                                                                 

---- User code sections - GMER 1.0.15 ----

.text          C:\Programme\Mozilla Firefox\firefox.exe[2848] ntdll.dll!LdrLoadDll                                                  7C92632D 5 Bytes  JMP 00401410 C:\Programme\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT            atapi.sys[HAL.dll!READ_PORT_UCHAR]                                                                                    [B9EA9040] spyv.sys
IAT            atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT]                                                                            [B9EA913C] spyv.sys
IAT            atapi.sys[HAL.dll!READ_PORT_USHORT]                                                                                  [B9EA90BE] spyv.sys
IAT            atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT]                                                                          [B9EA97FC] spyv.sys
IAT            atapi.sys[HAL.dll!WRITE_PORT_UCHAR]                                                                                  [B9EA96D2] spyv.sys
IAT            \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR]                                                    [B9EB9048] spyv.sys
IAT            \SystemRoot\System32\Drivers\ahnbxon5.SYS[HAL.dll!KfAcquireSpinLock]                                                  4B8BDF8B
IAT            \SystemRoot\System32\Drivers\ahnbxon5.SYS[HAL.dll!READ_PORT_UCHAR]                                                    8D3F0304
IAT            \SystemRoot\System32\Drivers\ahnbxon5.SYS[HAL.dll!KeGetCurrentIrql]                                                  CB033043
IAT            \SystemRoot\System32\Drivers\ahnbxon5.SYS[HAL.dll!KfRaiseIrql]                                                        0673C13B
IAT            \SystemRoot\System32\Drivers\ahnbxon5.SYS[HAL.dll!KfLowerIrql]                                                        C13B0003
IAT            \SystemRoot\System32\Drivers\ahnbxon5.SYS[HAL.dll!HalGetInterruptVector]                                              8366FA72
IAT            \SystemRoot\System32\Drivers\ahnbxon5.SYS[HAL.dll!HalTranslateBusAddress]                                            75000E7B
IAT            \SystemRoot\System32\Drivers\ahnbxon5.SYS[HAL.dll!KeStallExecutionProcessor]                                          0B7D80E3
IAT            \SystemRoot\System32\Drivers\ahnbxon5.SYS[HAL.dll!KfReleaseSpinLock]                                                  307B8D00
IAT            \SystemRoot\System32\Drivers\ahnbxon5.SYS[HAL.dll!READ_PORT_BUFFER_USHORT]                                            00AA840F
IAT            \SystemRoot\System32\Drivers\ahnbxon5.SYS[HAL.dll!READ_PORT_USHORT]                                                  83660000
IAT            \SystemRoot\System32\Drivers\ahnbxon5.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT]                                          6A000E7A
IAT            \SystemRoot\System32\Drivers\ahnbxon5.SYS[HAL.dll!WRITE_PORT_UCHAR]                                                  C6647400
IAT            \SystemRoot\System32\Drivers\ahnbxon5.SYS[WMILIB.SYS!WmiSystemControl]                                                4F8B0200
IAT            \SystemRoot\System32\Drivers\ahnbxon5.SYS[WMILIB.SYS!WmiCompleteRequest]                                              968D5140

---- Devices - GMER 1.0.15 ----

Device          \FileSystem\Ntfs \Ntfs                                                                                                89D6F1F8

AttachedDevice  \Driver\Kbdclass \Device\KeyboardClass0                                                                              Ch2kPS2.sys (Cherry PS2 driver for Win2k/Cherry GmbH)
AttachedDevice  \Driver\Kbdclass \Device\KeyboardClass1                                                                              Ch2kPS2.sys (Cherry PS2 driver for Win2k/Cherry GmbH)

Device          \Driver\usbohci \Device\USBPDO-0                                                                                      89B4E1F8
Device          \Driver\usbohci \Device\USBPDO-1                                                                                      89B4E1F8
Device          \Driver\usbehci \Device\USBPDO-2                                                                                      89B361F8

AttachedDevice  \Driver\Tcpip \Device\Tcp                                                                                            Lbd.sys (Boot Driver/Lavasoft AB)

Device          \Driver\Ftdisk \Device\HarddiskVolume1                                                                                89DE21F8
Device          \Driver\Ftdisk \Device\HarddiskVolume2                                                                                89DE21F8
Device          \Driver\Cdrom \Device\CdRom0                                                                                          89B9A500
Device          \Driver\sptd \Device\943844960                                                                                        spyv.sys
Device          \Driver\Cdrom \Device\CdRom1                                                                                          89B9A500
Device          \Driver\NetBT \Device\NetBt_Wins_Export                                                                              898E3500
Device          \Driver\NetBT \Device\NetbiosSmb                                                                                      898E3500
Device          \Driver\PCI_PNP6210 \Device\0000004d                                                                                  spyv.sys
Device          \Driver\NetBT \Device\NetBT_Tcpip_{213476E9-2727-4224-8EE0-B489FD84F287}                                              898E3500
Device          \Driver\usbohci \Device\USBFDO-0                                                                                      89B4E1F8
Device          \Driver\usbohci \Device\USBFDO-1                                                                                      89B4E1F8
Device          \FileSystem\MRxSmb \Device\LanmanDatagramReceiver                                                                    898EC500
Device          \Driver\usbehci \Device\USBFDO-2                                                                                      89B361F8
Device          \FileSystem\MRxSmb \Device\LanmanRedirector                                                                          898EC500
Device          \Driver\NetBT \Device\NetBT_Tcpip_{C2C4AA95-10DB-4A6E-9BE3-495A3955C2DC}                                              898E3500
Device          \Driver\Ftdisk \Device\FtControl                                                                                      89DE21F8
Device          \Driver\NetBT \Device\NetBT_Tcpip_{8D3DEADB-4129-483C-AC23-4EA701894FC7}                                              898E3500
Device          \Driver\ahnbxon5 \Device\Scsi\ahnbxon51Port3Path0Target0Lun0                                                          89B0E1F8
Device          \Driver\ahnbxon5 \Device\Scsi\ahnbxon51                                                                              89B0E1F8
Device          \FileSystem\Cdfs \Cdfs                                                                                                89971500

---- Registry - GMER 1.0.15 ----

Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000272805bf3                                         
Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000272805bf3@0010c690e4a4                              0xED 0x74 0x28 0x98 ...
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1                                                                    771343423
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2                                                                    285507792
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0                                                                    1
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4                                     
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0                                  C:\Programme\DAEMON Tools Lite\
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0                                  0
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh                                0xE5 0xC2 0x61 0xFC ...
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001                           
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0                          0x20 0x01 0x00 0x00 ...
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh                      0xC3 0xD5 0x1D 0xBA ...
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40                     
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh                0x2C 0x26 0xC3 0x2A ...
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41                     
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh                0xE8 0xCB 0xB2 0x7E ...
Reg            HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\000272805bf3                                             
Reg            HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\000272805bf3@0010c690e4a4                                  0xED 0x74 0x28 0x98 ...
Reg            HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4                                         
Reg            HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0                                      C:\Programme\DAEMON Tools Lite\
Reg            HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0                                      0
Reg            HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh                                    0xE5 0xC2 0x61 0xFC ...
Reg            HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001                               
Reg            HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0                              0x20 0x01 0x00 0x00 ...
Reg            HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh                          0xC3 0xD5 0x1D 0xBA ...
Reg            HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40                         
Reg            HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh                    0x2C 0x26 0xC3 0x2A ...
Reg            HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41                         
Reg            HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh                    0xE8 0xCB 0xB2 0x7E ...
Reg            HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-746137067-1645522239-1177238915-1004@RefCount  2

---- EOF - GMER 1.0.15 ----

--- --- ---


Ich habe keine Ahnung davon...vlt. könnt ihr mir helfen :)

Vielen Dank schon mal.

Gruß

el_ukas

cosinus 03.04.2011 17:24

Hallo und :hallo:

Bitte routinemäßig einen Vollscan mit malwarebytes machen und Log posten.
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!

Danach OTL:

Systemscan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
  • Doppelklick auf die OTL.exe
  • Vista User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen
  • Oben findest Du ein Kästchen mit Output. Wähle bitte Minimal Output
  • Unter Extra Registry, wähle bitte Use SafeList
  • Klicke nun auf Run Scan links oben
  • Wenn der Scan beendet wurde werden 2 Logfiles erstellt
  • Poste die Logfiles hier in den Thread.

el_ukas 03.04.2011 19:22

Hallo,

danke für die Hinweise :)

Hier der Malware-Log:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Datenbank Version: 6255

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

03.04.2011 20:10:43
mbam-log-2011-04-03 (20-10-43).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|L:\|)
Durchsuchte Objekte: 307912
Laufzeit: 1 Stunde(n), 24 Minute(n), 50 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)



Hier die OTL-Logs:OTL Logfile:
Code:

OTL logfile created on: 03.04.2011 20:17:10 - Run 2
OTL by OldTimer - Version 3.2.22.3    Folder = L:\Downloads\Sicherheit
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 62,00% Memory free
3,00 Gb Paging File | 2,00 Gb Available in Paging File | 79,00% Paging File free
Paging file location(s): C:\pagefile.sys 1152 2304 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 51,39 Gb Total Space | 7,36 Gb Free Space | 14,32% Space Free | Partition Type: NTFS
Drive L: | 97,66 Gb Total Space | 0,50 Gb Free Space | 0,52% Space Free | Partition Type: NTFS
 
Computer Name: LUKE | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - L:\Downloads\Sicherheit\OTL.exe (OldTimer Tools)
PRC - C:\Programme\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Programme\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
PRC - C:\Programme\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Programme\Prevx\prevx.exe (Prevx)
PRC - C:\WINDOWS\system32\TUProgSt.exe (TuneUp Software)
PRC - C:\Programme\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Programme\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Programme\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Programme\CDBurnerXP\NMSAccessU.exe ()
PRC - C:\WINDOWS\system32\sistray.exe (Silicon Integrated Systems Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - C:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexingService.exe (Nero AG)
PRC - C:\Programme\Gemeinsame Dateien\Nero\Lib\NMBgMonitor.exe (Nero AG)
PRC - C:\Programme\FSC\Wireless Utility\WirelessSelector.exe (ITE Tech Inc.)
PRC - C:\Programme\FSC\TouchPad HotKey Utility\TouchPad_HotKey.exe ()
 
 
========== Modules (SafeList) ==========
 
MOD - L:\Downloads\Sicherheit\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (AppMgmt) --  File not found
SRV - (Hamachi2Svc) -- C:\Programme\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (AntiVirService) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (McAfee SiteAdvisor Service) -- C:\Programme\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
SRV - (AntiVirSchedulerService) -- C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (CSIScanner) -- C:\Programme\Prevx\prevx.exe (Prevx)
SRV - (TuneUp.ProgramStatisticsSvc) -- C:\WINDOWS\system32\TUProgSt.exe (TuneUp Software)
SRV - (TuneUp.Defrag) -- C:\WINDOWS\system32\TuneUpDefragService.exe (TuneUp Software)
SRV - (Lavasoft Ad-Aware Service) -- C:\Programme\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (UxTuneUp) -- C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)
SRV - (FLEXnet Licensing Service) -- C:\Programme\Gemeinsame Dateien\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (NMSAccessU) -- C:\Programme\CDBurnerXP\NMSAccessU.exe ()
SRV - (Cherry Device Interface) -- C:\Programme\Cherry\CDI\cdi.exe (Cherry, Auerbach Germany, www.cherry.de)
SRV - (NMIndexingService) -- C:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexingService.exe (Nero AG)
SRV - (ose) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (avipbb) -- C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (atksgt) -- C:\WINDOWS\system32\drivers\atksgt.sys ()
DRV - (lirsgt) -- C:\WINDOWS\system32\drivers\lirsgt.sys ()
DRV - (pxsec) -- C:\WINDOWS\System32\drivers\pxsec.sys (Prevx)
DRV - (pxscan) -- C:\WINDOWS\System32\drivers\pxscan.sys (Prevx)
DRV - (hamachi) -- C:\WINDOWS\system32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (Lbd) -- C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (avgio) -- C:\Programme\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (ssmdrv) -- C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (sptd) -- C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (gmer) -- C:\WINDOWS\system32\drivers\gmer.sys (GMER)
DRV - (wip0204) -- C:\WINDOWS\system32\drivers\wip0204.sys (Wippien Software)
DRV - (Ambfilt) -- C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (SiSkp) -- C:\WINDOWS\system32\drivers\srvkp.sys (Silicon Integrated Systems Corporation)
DRV - (SiS315) -- C:\WINDOWS\system32\drivers\sisgrp.sys (Silicon Integrated Systems Corporation)
DRV - (KeyScrambler) -- C:\WINDOWS\system32\drivers\keyscrambler.sys (QFX Software Corporation)
DRV - (Ch2kPS2) Cherry PS/2 Tastatur Treiber (CDI) -- C:\WINDOWS\system32\drivers\Ch2kPS2.sys (Cherry GmbH)
DRV - (Ch2kUSB) -- C:\WINDOWS\system32\drivers\Ch2kUSB.sys (Cherry GmbH)
DRV - (zntport) -- C:\WINDOWS\system32\drivers\zntport.sys (Zeal SoftStudio)
DRV - (AR5211) -- C:\WINDOWS\system32\drivers\ar5211.sys (Atheros Communications, Inc.)
DRV - (SiSGbeXP) -- C:\WINDOWS\system32\drivers\SiSGbeXP.sys (Silicon Integrated Systems Corp.)
DRV - (TrmbTS) -- C:\WINDOWS\system32\drivers\TrmbTS.sys (Trimble AB, Sweden)
DRV - (Ch2kUSBM) -- C:\WINDOWS\system32\drivers\Ch2kUSBm.sys (Cherry GmbH)
DRV - (Ch2kPS2M) Cherry PS/2 Maus Treiber (CDI) -- C:\WINDOWS\system32\drivers\Ch2kPS2M.sys (Cherry GmbH)
DRV - (Monfilt) -- C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
DRV - (Camavb) -- C:\WINDOWS\system32\drivers\Camavb.sys (Samsung Inc.)
DRV - (PQNTDrv) -- C:\WINDOWS\System32\drivers\PQNTDRV.sys (PowerQuest Corporation)
DRV - (TRMUSB5K) -- C:\WINDOWS\system32\drivers\TRMUSB5K.SYS (e-TEK Labs)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
IE - HKCU\..\URLSearchHook: {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Programme\Winload\tbWinl.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "foxsearch"
FF - prefs.js..browser.search.order.1: "foxsearch"
FF - prefs.js..browser.search.selectedEngine: "foxsearch"
FF - prefs.js..browser.startup.homepage: "hxxp://www.gongfuchina.com.cn/home.asp"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.5
FF - prefs.js..extensions.enabledItems: gutscheinmieze@synatix-gmbh.de:1.03
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: keyscrambler@qfx.software.corporation:2.1.0.1
FF - prefs.js..extensions.enabledItems: {AA994882-F391-4d2e-806F-8908DA4814ED}:2.11.9
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.3.1
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.0.9.9
FF - prefs.js..keyword.URL: "hxxp://www.finduny.com?client=mozilla-firefox&cd=UTF-8&search=1&q="
 
FF - user.js..browser.search.selectedEngine: "foxsearch"
FF - user.js..browser.search.order.1: "foxsearch"
FF - user.js..browser.search.defaultenginename: "foxsearch"
FF - user.js..keyword.URL: "hxxp://www.finduny.com?client=mozilla-firefox&cd=UTF-8&search=1&q="
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Programme\McAfee\SiteAdvisor [2011.03.29 16:18:04 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Programme\Mozilla Firefox\components [2011.04.03 12:28:38 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2011.04.03 18:22:49 | 000,000,000 | ---D | M]
 
[2009.01.02 20:13:46 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\User\Anwendungsdaten\Mozilla\Extensions
[2011.04.03 17:10:29 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\User\Anwendungsdaten\Mozilla\Firefox\Profiles\84g8eslz.default\extensions
[2011.04.03 17:10:31 | 000,000,000 | ---D | M] (Winload Toolbar) -- C:\Dokumente und Einstellungen\User\Anwendungsdaten\Mozilla\Firefox\Profiles\84g8eslz.default\extensions\{40c3cc16-7269-4b32-9531-17f2950fb06f}
[2011.03.29 17:20:04 | 000,000,000 | ---D | M] (NoScript) -- C:\Dokumente und Einstellungen\User\Anwendungsdaten\Mozilla\Firefox\Profiles\84g8eslz.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2011.03.24 19:12:00 | 000,000,000 | ---D | M] (kikin plugin) -- C:\Dokumente und Einstellungen\User\Anwendungsdaten\Mozilla\Firefox\Profiles\84g8eslz.default\extensions\{AA994882-F391-4d2e-806F-8908DA4814ED}
[2011.03.29 17:20:04 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Dokumente und Einstellungen\User\Anwendungsdaten\Mozilla\Firefox\Profiles\84g8eslz.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2011.04.03 17:10:26 | 000,000,000 | ---D | M] (Mein Gutscheincode Finder) -- C:\Dokumente und Einstellungen\User\Anwendungsdaten\Mozilla\Firefox\Profiles\84g8eslz.default\extensions\finder@meingutscheincode.de
[2010.12.29 14:13:49 | 000,000,000 | ---D | M] (Gutscheinmieze) -- C:\Dokumente und Einstellungen\User\Anwendungsdaten\Mozilla\Firefox\Profiles\84g8eslz.default\extensions\gutscheinmieze@synatix-gmbh.de
[2009.05.25 13:30:19 | 000,000,000 | ---D | M] (KeyScrambler) -- C:\Dokumente und Einstellungen\User\Anwendungsdaten\Mozilla\Firefox\Profiles\84g8eslz.default\extensions\keyscrambler@qfx.software.corporation
[2011.04.03 12:28:38 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
File not found (No name found) --
[2009.02.22 02:34:21 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAMME\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011.03.29 16:18:04 | 000,000,000 | ---D | M] (McAfee SiteAdvisor) -- C:\PROGRAMME\MCAFEE\SITEADVISOR
[2009.09.01 22:05:48 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011.03.18 19:56:37 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Programme\Mozilla Firefox\components\browsercomps.dll
[2010.03.19 10:23:30 | 000,686,592 | ---- | M] (Synatix GmbH) -- C:\Programme\Mozilla Firefox\plugins\npmieze.dll
[2009.03.03 17:31:22 | 000,162,072 | ---- | M] (Tracker Software Products Ltd.) -- C:\Programme\Mozilla Firefox\plugins\npPDFXCviewNPPlugin.dll
[2011.03.17 21:57:30 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Programme\Mozilla Firefox\plugins\npwachk.dll
[2010.01.01 10:00:00 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2010.01.01 10:00:00 | 000,002,252 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\bing.xml
[2010.01.01 10:00:00 | 000,001,153 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml
[2010.12.29 14:13:49 | 000,000,143 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\foxsearch.src
[2010.01.01 10:00:00 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2010.12.01 19:31:58 | 000,002,027 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\McSiteAdvisor.xml
[2010.01.01 10:00:00 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2010.01.01 10:00:00 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2009.04.22 18:09:41 | 000,292,139 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: 127.0.0.1        www.007guard.com
O1 - Hosts: 127.0.0.1        007guard.com
O1 - Hosts: 127.0.0.1        008i.com
O1 - Hosts: 127.0.0.1        www.008k.com
O1 - Hosts: 127.0.0.1        008k.com
O1 - Hosts: 127.0.0.1        www.00hq.com
O1 - Hosts: 127.0.0.1        00hq.com
O1 - Hosts: 127.0.0.1        010402.com
O1 - Hosts: 127.0.0.1        www.032439.com
O1 - Hosts: 127.0.0.1        032439.com
O1 - Hosts: 127.0.0.1        www.0scan.com
O1 - Hosts: 127.0.0.1        0scan.com
O1 - Hosts: 127.0.0.1        1000gratisproben.com
O1 - Hosts: 127.0.0.1        www.1000gratisproben.com
O1 - Hosts: 127.0.0.1        www.1001namen.com
O1 - Hosts: 127.0.0.1        1001namen.com
O1 - Hosts: 127.0.0.1        www.100888290cs.com
O1 - Hosts: 127.0.0.1        100888290cs.com
O1 - Hosts: 127.0.0.1        www.100sexlinks.com
O1 - Hosts: 127.0.0.1        100sexlinks.com
O1 - Hosts: 127.0.0.1        www.10sek.com
O1 - Hosts: 127.0.0.1        10sek.com
O1 - Hosts: 127.0.0.1        www.1-2005-search.com
O1 - Hosts: 127.0.0.1        1-2005-search.com
O1 - Hosts: 10057 more lines...
O2 - BHO: (CKeyScramblerBHO Object) - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Programme\KeyScrambler\KeyScramblerIE.dll (QFX Software Corporation)
O2 - BHO: (Winload Toolbar) - {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Programme\Winload\tbWinl.dll (Conduit Ltd.)
O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (PDF-XChange Viewer IE-Plugin) - {C5D07EB6-BBCE-4DAE-ACBB-D13A8D28CB1F} - C:\Programme\Tracker Software\PDF-XChange Viewer\pdf-viewer\PDFXCviewIEPlugin.dll (Tracker Software Products Ltd.)
O2 - BHO: (kikin Plugin) - {E601996F-E400-41CA-804B-CD6373A7EEE2} - Reg Error: Value error. File not found
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Winload Toolbar) - {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Programme\Winload\tbWinl.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Gutscheinmieze) - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} -  File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Gutscheinmieze) - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} -  File not found
O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [KernelFaultCheck]  File not found
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Programme\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [SiSPower] C:\WINDOWS\System32\SiSPower.dll (Silicon Integrated Systems Corporation)
O4 - HKLM..\Run: [TouchPadHotKey] C:\Programme\FSC\TouchPad HotKey Utility\TouchPad_HotKey.exe ()
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe (Silicon Integrated Systems Corporation)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\WirelessSelector.lnk = C:\Programme\FSC\Wireless Utility\WirelessSelector.exe (ITE Tech Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 181
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67106811
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O9 - Extra 'Tools' menuitem : My kikin - {0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : &KeyScrambler... - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Programme\KeyScrambler\KeyScramblerIE.dll (QFX Software Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Gemeinsame Dateien\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 0
O32 - AutoRun File - [2009.01.02 15:57:38 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.04.03 18:22:49 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\User\Startmenü\Programme\Winamp Erkennungs-Plug-in
[2011.04.03 18:22:49 | 000,000,000 | ---D | C] -- C:\Winamp Detect
[2011.04.03 18:22:49 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Winamp
[2011.04.03 18:22:38 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\User\Anwendungsdaten\Winamp
[2011.04.03 18:15:44 | 000,000,000 | ---D | C] -- C:\Winamp
[2011.04.03 17:51:30 | 000,000,000 | ---D | C] -- C:\Programme\PC Beschleunigen
[2011.04.03 17:51:15 | 000,059,888 | ---- | C] (Sonic Solutions) -- C:\WINDOWS\System32\pxwma.dll
[2011.04.03 17:51:15 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Anwendungsdaten\OpenCandy
[2011.04.03 17:51:12 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\User\Anwendungsdaten\OpenCandy
[2011.04.03 17:40:46 | 000,000,000 | ---D | C] -- C:\Programme\Winamp
[2011.04.03 17:10:36 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Anwendungsdaten\Conduit
[2011.04.03 17:10:35 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Anwendungsdaten\Winload
[2011.04.03 17:10:35 | 000,000,000 | ---D | C] -- C:\Programme\Conduit
[2011.04.03 17:10:33 | 000,000,000 | ---D | C] -- C:\Programme\Winload
[2011.04.03 15:25:39 | 000,000,000 | RH-D | C] -- C:\Dokumente und Einstellungen\User\Recent
[2011.04.03 15:23:17 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen\User\IECompatCache
[2011.04.03 15:12:54 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\User\Startmenü\Programme\CCleaner
[2011.04.03 15:12:52 | 000,000,000 | ---D | C] -- C:\Programme\CCleaner
[2011.04.01 01:53:41 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\User\Schachspiele
[2011.03.29 18:07:09 | 000,000,000 | ---D | C] -- C:\pebuilder-stick
[2011.03.29 18:06:39 | 000,000,000 | ---D | C] -- C:\pebuilder
[2011.03.29 16:03:51 | 000,000,000 | ---D | C] -- C:\Programme\LogMeIn Hamachi
[2011.03.29 16:03:51 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\LogMeIn Hamachi
[2011.03.24 18:45:56 | 000,000,000 | ---D | C] -- C:\usbdos
[2011.03.24 18:43:10 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Hewlett-Packard Company
[2011.03.24 18:43:10 | 000,000,000 | ---D | C] -- C:\DriveKey
[2011.03.19 18:42:21 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\User\Startmenü\Programme\jose
[2011.03.19 17:25:45 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\User\Startmenü\Programme\Miranda IM
[2011.03.15 17:56:42 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\eMule
[2009.07.04 21:25:02 | 000,047,360 | ---- | C] (VSO Software) -- C:\Dokumente und Einstellungen\User\Anwendungsdaten\pcouffin.sys
[2007.08.13 17:46:00 | 000,102,912 | ---- | C] (Albert L Faber) -- C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Anwendungsdaten\CDRip.dll
[2007.01.18 21:09:54 | 000,623,616 | ---- | C] (Ivan Bischof ©2003 - 2005) -- C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Anwendungsdaten\No23 Recorder.exe
[2006.12.11 19:13:14 | 000,013,872 | ---- | C] (Un4seen Developments) -- C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Anwendungsdaten\basscd.dll
[2006.12.11 19:13:12 | 000,097,336 | ---- | C] (Un4seen Developments) -- C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Anwendungsdaten\bass.dll
[61 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2011.04.03 20:12:44 | 000,000,490 | ---- | M] () -- C:\WINDOWS\tasks\1-Klick-Wartung.job
[2011.04.03 20:12:37 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011.04.03 19:50:01 | 000,001,248 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-746137067-1645522239-1177238915-1005UA.job
[2011.04.03 19:27:15 | 000,037,145 | ---- | M] () -- C:\Dokumente und Einstellungen\User\.jose.user.preferences
[2011.04.03 18:22:49 | 000,000,494 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Winamp.lnk
[2011.04.03 16:56:42 | 000,001,377 | ---- | M] () -- C:\WINDOWS\WINCMD.INI
[2011.04.03 16:50:00 | 000,001,196 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-746137067-1645522239-1177238915-1005Core.job
[2011.04.03 15:12:54 | 000,001,512 | ---- | M] () -- C:\Dokumente und Einstellungen\User\Desktop\CCleaner.lnk
[2011.04.03 12:59:06 | 000,000,458 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011.04.03 12:28:41 | 000,000,696 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Mozilla Firefox.lnk
[2011.03.29 20:01:00 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011.03.28 15:49:22 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011.03.24 18:43:10 | 000,000,325 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\HP USB Disk Storage Format Tool.lnk
[2011.03.23 20:26:36 | 000,000,624 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\eMule.lnk
[2011.03.22 00:17:18 | 000,002,802 | ---- | M] () -- C:\Dokumente und Einstellungen\User\collection.autosave.jose
[2011.03.19 18:42:21 | 000,000,598 | ---- | M] () -- C:\Dokumente und Einstellungen\User\Desktop\jose.lnk
[2011.03.19 17:25:46 | 000,000,673 | ---- | M] () -- C:\Dokumente und Einstellungen\User\Desktop\Miranda IM.lnk
[2011.03.18 12:43:04 | 000,137,656 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2011.03.15 22:27:43 | 000,000,897 | ---- | M] () -- C:\Dokumente und Einstellungen\User\Desktop\PDF-Viewer.lnk
[2011.03.04 21:44:14 | 002,095,600 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\pxsfs.dll
[2011.03.04 21:44:14 | 000,571,888 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\pxdrv.dll
[2011.03.04 21:44:14 | 000,440,816 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\pxwave.dll
[2011.03.04 21:44:14 | 000,219,632 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\pxmas.dll
[2011.03.04 21:44:14 | 000,133,616 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\pxafs.dll
[2011.03.04 21:44:14 | 000,100,848 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\vxblock.dll
[2011.03.04 21:44:14 | 000,072,176 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\pxhpinst.exe
[2011.03.04 21:44:14 | 000,059,888 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\pxwma.dll
[2011.03.04 21:44:12 | 000,698,864 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\px.dll
[2011.03.04 21:44:12 | 000,126,448 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\pxinsi64.exe
[2011.03.04 21:44:12 | 000,123,888 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\pxcpyi64.exe
[2011.03.04 21:44:12 | 000,068,592 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\pxinsa64.exe
[2011.03.04 21:44:12 | 000,068,080 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\pxcpya64.exe
[61 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2011.04.03 20:11:29 | 000,165,512 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\FontCache3.0.0.0.dat
[2011.04.03 18:22:49 | 000,000,494 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Winamp.lnk
[2011.04.03 15:12:54 | 000,001,512 | ---- | C] () -- C:\Dokumente und Einstellungen\User\Desktop\CCleaner.lnk
[2011.04.03 12:28:41 | 000,000,696 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Mozilla Firefox.lnk
[2011.04.03 12:28:40 | 000,000,702 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Mozilla Firefox.lnk
[2011.03.24 18:43:10 | 000,000,325 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\HP USB Disk Storage Format Tool.lnk
[2011.03.22 00:17:17 | 000,002,802 | ---- | C] () -- C:\Dokumente und Einstellungen\User\collection.autosave.jose
[2011.03.19 18:42:21 | 000,000,598 | ---- | C] () -- C:\Dokumente und Einstellungen\User\Desktop\jose.lnk
[2011.03.15 17:56:46 | 000,000,624 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\eMule.lnk
[2010.12.03 18:26:35 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll
[2010.09.13 20:38:59 | 000,016,384 | ---- | C] () -- C:\WINDOWS\System32\FileOps.exe
[2010.09.13 20:38:54 | 000,000,034 | ---- | C] () -- C:\WINDOWS\iltwain.ini
[2010.08.27 16:31:07 | 000,271,360 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys
[2010.08.27 16:31:03 | 000,018,048 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys
[2010.08.07 03:42:46 | 000,031,547 | ---- | C] () -- C:\WINDOWS\scunin.dat
[2010.06.27 20:36:04 | 000,017,408 | ---- | C] () -- C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Anwendungsdaten\WebpageIcons.db
[2010.06.18 22:53:12 | 000,001,484 | ---- | C] () -- C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Anwendungsdaten\RecConfig.xml
[2010.02.16 17:46:25 | 000,010,912 | ---- | C] () -- C:\Programme\Gothic.RPT
[2010.01.30 14:16:37 | 000,004,096 | ---- | C] () -- C:\WINDOWS\d3dx.dat
[2009.11.15 18:13:54 | 000,002,528 | ---- | C] () -- C:\Dokumente und Einstellungen\User\Anwendungsdaten\$_hpcst$.hpc
[2009.10.25 14:25:30 | 000,015,688 | ---- | C] () -- C:\WINDOWS\System32\lsdelete.exe
[2009.08.17 15:20:16 | 000,000,138 | ---- | C] () -- C:\WINDOWS\dsp_multiple_config.ini
[2009.07.07 21:49:12 | 000,001,333 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2009.07.07 21:47:45 | 000,000,541 | ---- | C] () -- C:\WINDOWS\BZII.INI
[2009.07.04 21:25:20 | 000,000,014 | ---- | C] () -- C:\WINDOWS\System32\systeminfo3.dll
[2009.07.04 21:25:02 | 000,081,920 | ---- | C] () -- C:\Dokumente und Einstellungen\User\Anwendungsdaten\ezpinst.exe
[2009.07.04 21:25:02 | 000,007,176 | ---- | C] () -- C:\Dokumente und Einstellungen\User\Anwendungsdaten\pcouffin.cat
[2009.07.04 21:25:02 | 000,001,144 | ---- | C] () -- C:\Dokumente und Einstellungen\User\Anwendungsdaten\pcouffin.inf
[2009.06.24 23:46:49 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2009.05.30 18:48:32 | 000,000,851 | ---- | C] () -- C:\WINDOWS\QIII.INI
[2009.05.15 19:40:54 | 000,093,362 | ---- | C] () -- C:\WINDOWS\VGAsetup.ini
[2009.05.15 19:40:47 | 000,208,896 | R--- | C] () -- C:\WINDOWS\Progress.exe
[2009.05.15 19:40:47 | 000,049,152 | R--- | C] () -- C:\WINDOWS\InstFunc.exe
[2009.05.15 19:40:40 | 000,065,536 | R--- | C] () -- C:\WINDOWS\System32\sis760.bin
[2009.05.15 19:40:40 | 000,065,536 | R--- | C] () -- C:\WINDOWS\System32\sis741.bin
[2009.05.15 19:40:40 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\sis660.bin
[2009.05.15 19:40:08 | 000,133,933 | ---- | C] () -- C:\WINDOWS\System32\VGAunistlog.ini
[2009.05.14 20:04:00 | 000,000,276 | ---- | C] () -- C:\WINDOWS\EReg176.dat
[2009.02.09 21:06:20 | 000,180,224 | ---- | C] () -- C:\WINDOWS\Res2_uninst.exe
[2009.01.18 16:37:09 | 000,000,912 | ---- | C] () -- C:\WINDOWS\eReg.dat
[2009.01.17 20:35:50 | 000,000,010 | ---- | C] () -- C:\WINDOWS\popcinfo.dat
[2009.01.08 01:03:46 | 000,000,250 | ---- | C] () -- C:\WINDOWS\gmer.ini
[2009.01.08 01:03:24 | 000,819,200 | ---- | C] () -- C:\WINDOWS\gmer.dll
[2009.01.08 01:03:23 | 000,757,760 | ---- | C] () -- C:\WINDOWS\gmer.exe
[2009.01.05 18:25:18 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2009.01.05 18:25:16 | 000,022,016 | ---- | C] () -- C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.01.04 18:01:13 | 000,282,624 | ---- | C] () -- C:\WINDOWS\Uninstall.exe
[2009.01.04 18:01:13 | 000,057,344 | ---- | C] () -- C:\WINDOWS\HAJEInstall.dll
[2009.01.02 22:24:12 | 000,001,065 | ---- | C] () -- C:\WINDOWS\winamp.ini
[2009.01.02 20:13:46 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2009.01.02 17:14:22 | 000,000,400 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009.01.02 16:02:25 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2009.01.02 15:55:08 | 000,021,740 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2009.01.02 15:49:27 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2009.01.02 15:48:14 | 001,521,128 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2008.11.21 23:47:52 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2008.11.21 23:44:16 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
[2008.10.07 09:13:30 | 000,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll
[2008.10.07 09:13:22 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2008.04.14 08:06:26 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2008.04.14 07:52:42 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\ctfmon.exe
[2007.08.13 17:46:00 | 000,155,136 | ---- | C] () -- C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Anwendungsdaten\lame_enc.dll
[2006.12.31 08:57:08 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2006.10.26 01:06:48 | 000,064,000 | ---- | C] () -- C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Anwendungsdaten\vorbisenc.dll
[2006.10.26 01:06:48 | 000,019,456 | ---- | C] () -- C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Anwendungsdaten\vorbisfile.dll
[2006.10.26 01:06:46 | 000,143,872 | ---- | C] () -- C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Anwendungsdaten\vorbis.dll
[2006.10.26 01:06:36 | 000,015,872 | ---- | C] () -- C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Anwendungsdaten\ogg.dll
[2005.10.10 14:00:00 | 000,005,702 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2005.08.23 22:34:06 | 000,029,184 | ---- | C] () -- C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Anwendungsdaten\no23xwrapper.dll
[2005.06.22 11:59:44 | 000,001,377 | ---- | C] () -- C:\WINDOWS\WINCMD.INI
[2001.08.18 14:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001.08.18 14:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001.08.18 14:00:00 | 000,449,044 | ---- | C] () -- C:\WINDOWS\System32\perfh007.dat
[2001.08.18 14:00:00 | 000,432,690 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001.08.18 14:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001.08.18 14:00:00 | 000,269,480 | ---- | C] () -- C:\WINDOWS\System32\perfi007.dat
[2001.08.18 14:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001.08.18 14:00:00 | 000,080,500 | ---- | C] () -- C:\WINDOWS\System32\perfc007.dat
[2001.08.18 14:00:00 | 000,067,646 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001.08.18 14:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001.08.18 14:00:00 | 000,034,478 | ---- | C] () -- C:\WINDOWS\System32\perfd007.dat
[2001.08.18 14:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001.08.18 14:00:00 | 000,004,461 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001.08.18 14:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[1998.06.09 05:00:00 | 000,244,984 | ---- | C] () -- C:\WINDOWS\TUTIL32.DLL
[1998.04.01 14:49:24 | 001,028,608 | ---- | C] () -- C:\WINDOWS\H5KRNL32.DLL
[1998.04.01 14:49:06 | 000,051,200 | ---- | C] () -- C:\WINDOWS\H5TOOL32.DLL
[1998.04.01 14:48:48 | 000,114,688 | ---- | C] () -- C:\WINDOWS\H5DLG32.DLL
[1998.03.16 22:24:28 | 000,093,696 | ---- | C] () -- C:\WINDOWS\H5RTF32.DLL
[1998.03.16 22:23:36 | 000,175,616 | ---- | C] () -- C:\WINDOWS\H5MENU32.DLL
[1998.03.16 22:23:14 | 000,188,928 | ---- | C] () -- C:\WINDOWS\H5ICON32.DLL
[1997.11.12 22:14:04 | 000,303,104 | ---- | C] () -- C:\WINDOWS\I3TIF32.DLL
[1997.11.09 22:24:52 | 000,163,840 | ---- | C] () -- C:\WINDOWS\ILANOT32.DLL
[1997.10.28 19:30:20 | 000,435,200 | ---- | C] () -- C:\WINDOWS\ILFILT32.DLL
[1997.10.28 19:30:20 | 000,110,592 | ---- | C] () -- C:\WINDOWS\I3DXF32.DLL
[1997.06.14 03:56:08 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 153 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:DFC5A2B2
@Alternate Data Stream - 112 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:B606BA34
@Alternate Data Stream - 110 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:888AFB86

< End of report >

--- --- ---
OTL Logfile:
Code:

OTL Extras logfile created on: 03.04.2011 20:17:10 - Run 2
OTL by OldTimer - Version 3.2.22.3    Folder = L:\Downloads\Sicherheit
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 62,00% Memory free
3,00 Gb Paging File | 2,00 Gb Available in Paging File | 79,00% Paging File free
Paging file location(s): C:\pagefile.sys 1152 2304 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 51,39 Gb Total Space | 7,36 Gb Free Space | 14,32% Space Free | Partition Type: NTFS
Drive L: | 97,66 Gb Total Space | 0,50 Gb Free Space | 0,52% Space Free | Partition Type: NTFS
 
Computer Name: LUKE | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Programme\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Programme\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 4
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"5353:UDP" = 5353:UDP:*:Enabled:Bonjour
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"20000:TCP" = 20000:TCP:*:Enabled:miranda1
"20001:TCP" = 20001:TCP:*:Enabled:m2
"20002:TCP" = 20002:TCP:*:Enabled:m3
"20000:UDP" = 20000:UDP:*:Enabled:m4
"20001:UDP" = 20001:UDP:*:Enabled:m5
"20002:UDP" = 20002:UDP:*:Enabled:m6
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Programme\uTorrent\uTorrent.exe" = C:\Programme\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"C:\Programme\SoulseekNS\slsk.exe" = C:\Programme\SoulseekNS\slsk.exe:*:Enabled:SoulSeek -- ()
"C:\Programme\TmNationsForever\TmForever.exe" = C:\Programme\TmNationsForever\TmForever.exe:*:Disabled:TmForever -- ()
"C:\Programme\AirPort\APAgent.exe" = C:\Programme\AirPort\APAgent.exe:*:Enabled:AirPort -- (Apple Inc.)
"C:\Programme\Quake III Arena\quake3.exe" = C:\Programme\Quake III Arena\quake3.exe:*:Enabled:quake3 -- ()
"C:\Programme\Valve\hl.exe" = C:\Programme\Valve\hl.exe:*:Enabled:Half-Life Launcher -- (Valve)
"C:\Programme\Valve\hlds.exe" = C:\Programme\Valve\hlds.exe:*:Disabled:HLDS Launcher -- (Valve)
"C:\Programme\Miranda IM\miranda32.exe" = C:\Programme\Miranda IM\miranda32.exe:*:Enabled:Miranda IM -- ( )
"C:\WINDOWS\system32\dplaysvr.exe" = C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper -- (Microsoft Corporation)
"C:\Programme\Microsoft Games\Age of Empires II\age2_x1\age2_x1.icd" = C:\Programme\Microsoft Games\Age of Empires II\age2_x1\age2_x1.icd:*:Enabled:Age of Empires II Expansion -- (Microsoft Corporation)
"C:\Programme\Microsoft Games\Age of Empires II\EMPIRES2.ICD" = C:\Programme\Microsoft Games\Age of Empires II\EMPIRES2.ICD:*:Enabled:Age of Empires II -- (Microsoft Corporation)
"C:\WINDOWS\system32\dpnsvr.exe" = C:\WINDOWS\system32\dpnsvr.exe:*:Enabled:Microsoft DirectPlay8-Server -- (Microsoft Corporation)
"C:\Programme\Java\jre6\launch4j-tmp\JDownloader.exe" = C:\Programme\Java\jre6\launch4j-tmp\JDownloader.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"C:\WINDOWS\system32\mmc.exe" = C:\WINDOWS\system32\mmc.exe:*:Disabled:Microsoft Management Console -- (Microsoft Corporation)
"C:\Programme\eMule\emule.exe" = C:\Programme\eMule\emule.exe:*:Enabled:eMule -- (hxxp://www.emule-project.net)
"C:\Programme\Winamp\winamp.exe" = C:\Programme\Winamp\winamp.exe:*:Enabled:Winamp
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{003CD4FD-DB3E-4D12-9A34-8C00FA8A680F}" = WirelessControl
"{034C3B3E-6C50-464C-938F-0A51F99C2E62}" = Remote Speakers output
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour
"{0E0DF90C-D0BA-4C89-9262-AD78D1A3DE51}" = HP USB Disk Storage Format Tool
"{13B792AA-C078-43A4-8A3A-8B12D629940D}" = Counter-Strike 1.6
"{1545207E-C6F3-31D7-9918-BDBB65075FBF}" = Microsoft .NET Framework 3.5 Language Pack - deu
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{1C4551A6-4743-4093-91E4-1477CD655043}" = NVIDIA PhysX
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{21DBBDD6-93A5-4326-9A04-C9A5C9148502}" = Norton PartitionMagic
"{22B0E143-2B0B-435B-9F56-136A3D16065F}" = No23 Recorder
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{245F6C7A-0C22-4DE0-8202-2AAA620A1D3A}" = Microsoft XNA Framework Redistributable 2.0
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java(TM) 6 Update 13
"{27263813-8BDE-4CD2-84D3-02536743428A}_is1" = Attribute Changer 6.20
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{2A5690C8-1C66-4CA0-8DB1-39D61F495BDA}" = Götz Pflanzenbestimmung 2
"{2BC21CD2-8053-406A-80F6-9AB61717B49D}" = ODF Add-In für Microsoft Office
"{350C97B3-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}" = McAfee SiteAdvisor
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{3D7E3EC9-46CF-4359-9289-39CE01DFB82F}" = Adobe Photoshop CS3
"{491DFBAA-77EF-4B06-8676-2FC66EEE049A}" = LogMeIn Hamachi
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{55A29068-F2CE-456C-9148-C869879E2357}" = TuneUp Utilities 2009
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5FC68772-6D56-41C6-9DF1-24E868198AE6}" = Windows Live Call
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7CC7C026-F81D-4405-9639-B157B7480D73}" = Generic Wireless LAN Driver
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8D273DE5-ABFA-4BD0-A9D7-EE9C971438C4}_is1" = PDF-Viewer
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{90110407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{9309DD7E-EBFE-3C95-8B47-30D3A012F606}" = Microsoft .NET Framework 2.0 Service Pack 1 Language Pack - DEU
"{9509674F-3972-11DE-806D-005056806466}" = Google Earth
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{98CB24AD-52FB-DB5F-FF1F-C8B3B9A1E18E}" = Visual C++ 8.0 CRT (x86) WinSXS MSM
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{9D210D79-AEC5-453B-960C-4DD2C73931E1}" = Bonjour-Druckdienste
"{A1071AEB-B0EF-3F5F-BC84-83A270EBE496}" = Microsoft .NET Framework 3.0 Service Pack 1 Language Pack - DEU
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1" = PDF-Viewer
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A68C6683-AF69-4421-B606-1A2636E91523}" = AirPort
"{A8BB9906-E618-406A-B161-7383AFF46C39}" = EasyRecovery Professional
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B7DDE586-D6F1-4CC7-8A2F-FCFF59F77D7D}" = OutcastDVD
"{B944FA21-81AF-4A77-8328-CE4F4CC51031}" = Nero 8
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{BD87B950-D3E0-11D3-BE74-0000E20392C2}" = Outcast
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{CB71F9B7-E8BB-4275-9F45-7F6B4BB980FA}" = Total Commander 6.53
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE7CB214-DB11-4B5D-A6AF-3B4ED47C68B7}" = Microsoft Game Studios Common Redistributables Pack 1
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D2D40BAE-7B66-11D3-882B-00105A64914B}" = Trimble Data Transfer
"{DA507A38-4B2A-40C0-90AC-E30AAA0B757C}" = Vegas Movie Studio Platinum 9.0
"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
"{DB457913-028D-460E-BB4C-D9A6369752CA}" = TouchPad HotKey Utility
"{DC226AC9-0314-496C-BE6A-B6A132628466}" = SiSAGP driver
"{DC627AE5-A2B1-4D16-AF56-178D10EC3E81}" = KeyMan V3.5 Build 1
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F8FF18EE-264A-43FD-B2F6-5EAD40798C2F}" = Windows Live Essentials
"{FF11004C-F42A-4A31-9BCF-7F5C8FDBE53C}" = Adobe Setup
"7-Zip" = 7-Zip 4.65
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe SVG Viewer" = Adobe SVG Viewer 3.0
"Adobe_719d6f144d0c086a0dfa7ff76bb9ac1" = Adobe Photoshop CS3
"Age of Empires 2.0" = Microsoft Age of Empires II
"Age of Empires II: The Conquerors Expansion 1.0" = Microsoft Age of Empires II: The Conquerors Expansion
"Audiograbber" = Audiograbber 1.83 SE
"Audiograbber-Lame" = Audiograbber MP3-Plugin
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"CCleaner" = CCleaner (remove only)
"DVD Shrink_is1" = DVD Shrink 3.2
"eMule" = eMule
"Eusing Free Registry Cleaner" = Eusing Free Registry Cleaner
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{21DBBDD6-93A5-4326-9A04-C9A5C9148502}" = Norton PartitionMagic 8.0
"InstallShield_{A8BB9906-E618-406A-B161-7383AFF46C39}" = EasyRecovery Professional
"jose-chess" = jose
"KeyScrambler" = KeyScrambler
"LogMeIn Hamachi" = LogMeIn Hamachi
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 Language Pack - deu" = Microsoft .NET Framework 3.5 Language Pack - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Miranda IM" = Miranda IM 0.9.17
"Mozilla Firefox 4.0 (x86 de)" = Mozilla Firefox 4.0 (x86 de)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PCSI" = Prevx 3.0
"pdfsam" = pdfsam
"Pontifex" = Pontifex
"Quake III Arena" = Quake III Arena
"RESIDENT EVIL2" = RESIDENT EVIL2
"SiS VGA Driver" = SiS VGA Utilities
"Soulseek2" = SoulSeek 157 NS 13e
"Starcraft" = Starcraft
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2
"UFO:Alien Invasion" = UFO:AI 2.3
"uTorrent" = µTorrent
"VLC media player" = VLC media player 1.0.0
"VMidi" = vanBasco's Karaoke Player
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format Runtime
"WinLiveSuite_Wave3" = Windows Live Essentials
"Winload Toolbar" = Winload Toolbar
"WOLAPI" = Gemeinsam genutzte Internet-Komponenten von Westwood
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0
"Zattoo4" = Zattoo4 4.0.5
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Winamp Detect" = Winamp Erkennungs-Plug-in
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 03.04.2011 07:44:50 | Computer Name = LUKE | Source = Bonjour Service | ID = 100
Description = 232: ERROR: read_msg errno 10054 (Eine vorhandene Verbindung wurde
 vom Remotehost geschlossen.)
 
Error - 03.04.2011 07:45:00 | Computer Name = LUKE | Source = Bonjour Service | ID = 100
Description = 404: ERROR: read_msg errno 10054 (Eine vorhandene Verbindung wurde
 vom Remotehost geschlossen.)
 
Error - 03.04.2011 07:49:24 | Computer Name = LUKE | Source = Bonjour Service | ID = 100
Description = 256: ERROR: read_msg errno 10054 (Eine vorhandene Verbindung wurde
 vom Remotehost geschlossen.)
 
Error - 03.04.2011 07:49:24 | Computer Name = LUKE | Source = Bonjour Service | ID = 100
Description = 232: ERROR: read_msg errno 10054 (Eine vorhandene Verbindung wurde
 vom Remotehost geschlossen.)
 
Error - 03.04.2011 07:49:43 | Computer Name = LUKE | Source = Bonjour Service | ID = 100
Description = 404: ERROR: read_msg errno 10054 (Eine vorhandene Verbindung wurde
 vom Remotehost geschlossen.)
 
Error - 03.04.2011 09:34:36 | Computer Name = LUKE | Source = Bonjour Service | ID = 100
Description = 232: ERROR: read_msg errno 10054 (Eine vorhandene Verbindung wurde
 vom Remotehost geschlossen.)
 
Error - 03.04.2011 09:34:36 | Computer Name = LUKE | Source = Bonjour Service | ID = 100
Description = 256: ERROR: read_msg errno 10054 (Eine vorhandene Verbindung wurde
 vom Remotehost geschlossen.)
 
Error - 03.04.2011 13:44:04 | Computer Name = LUKE | Source = MSDTC | ID = 4404
Description = Infrastruktur der MS DTC-Ablaufverfolgung: Fehler beim Initialisieren
 der Infrastruktur der Ablaufverfolgung. Interne Informationen: msdtc_trace : File:
 d:\comxp_sp3\com\com1x\dtc\dtc\trace\src\tracelib.cpp, Line: 1115, StartTrace Failed,
 hr=0x8007001f 
 
Error - 03.04.2011 13:44:14 | Computer Name = LUKE | Source = VSS | ID = 12289
Description = Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "DeviceIoControl(00000250,0x0053c008,00039B90,0,00038B88,4096,[0])".
 hr = 0x80070005.
 
Error - 03.04.2011 14:13:22 | Computer Name = LUKE | Source = ESENT | ID = 490
Description = svchost (1488) Versuch, Datei "C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb"
 für den Lese-/Schreibzugriff zu öffnen, ist mit Systemfehler 32 (0x00000020): "Der
 Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet
 wird. " fehlgeschlagen. Fehler -1032 (0xfffffbf8) beim Öffnen von Dateien.
 
[ System Events ]
Error - 03.04.2011 14:05:00 | Computer Name = LUKE | Source = Srv | ID = 2000
Description = Der Aufruf eines Systemdienstes durch den Serverdienst ist unerwartet
 fehlgeschlagen.
 
Error - 03.04.2011 14:05:00 | Computer Name = LUKE | Source = Srv | ID = 2000
Description = Der Aufruf eines Systemdienstes durch den Serverdienst ist unerwartet
 fehlgeschlagen.
 
Error - 03.04.2011 14:05:00 | Computer Name = LUKE | Source = Srv | ID = 2000
Description = Der Aufruf eines Systemdienstes durch den Serverdienst ist unerwartet
 fehlgeschlagen.
 
Error - 03.04.2011 14:05:00 | Computer Name = LUKE | Source = Srv | ID = 2000
Description = Der Aufruf eines Systemdienstes durch den Serverdienst ist unerwartet
 fehlgeschlagen.
 
Error - 03.04.2011 14:05:00 | Computer Name = LUKE | Source = Srv | ID = 2000
Description = Der Aufruf eines Systemdienstes durch den Serverdienst ist unerwartet
 fehlgeschlagen.
 
Error - 03.04.2011 14:05:00 | Computer Name = LUKE | Source = Srv | ID = 2000
Description = Der Aufruf eines Systemdienstes durch den Serverdienst ist unerwartet
 fehlgeschlagen.
 
Error - 03.04.2011 14:05:00 | Computer Name = LUKE | Source = Srv | ID = 2000
Description = Der Aufruf eines Systemdienstes durch den Serverdienst ist unerwartet
 fehlgeschlagen.
 
Error - 03.04.2011 14:05:00 | Computer Name = LUKE | Source = Srv | ID = 2000
Description = Der Aufruf eines Systemdienstes durch den Serverdienst ist unerwartet
 fehlgeschlagen.
 
Error - 03.04.2011 14:05:00 | Computer Name = LUKE | Source = Srv | ID = 2000
Description = Der Aufruf eines Systemdienstes durch den Serverdienst ist unerwartet
 fehlgeschlagen.
 
Error - 03.04.2011 14:14:24 | Computer Name = LUKE | Source = MRxSmb | ID = 8003
Description = Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "EASYBOX",
der
 der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{213476E9-2727-4224-8-Transport
 zu sein scheint.  Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen.
 
[ TuneUp Events ]
Error - 16.02.2011 06:56:53 | Computer Name = LUKE | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
 ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2011-02-16 11:56:53', '\device\harddiskvolume1\programme\malwarebytes'
 anti-malware\mbam.exe','3196',0)
 
Error - 22.02.2011 21:32:56 | Computer Name = LUKE | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: database or disk is full; when executing SQL: UPDATE StartMenuEntries
 SET Outdated='1'
 
Error - 22.02.2011 21:32:56 | Computer Name = LUKE | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: database or disk is full; when executing SQL: UPDATE SecurityProducts
 SET Outdated='1'
 
Error - 22.02.2011 21:32:56 | Computer Name = LUKE | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: database or disk is full; when executing SQL: INSERT INTO
 Applications (Exe, Started, Ended, State, Resumed) SELECT Exe, Started, Ended,
State, Resumed FROM MemApplications;DELETE FROM MemApplications;INSERT INTO Applications
 (Exe, Started, Ended, State, Resumed) SELECT Exe, Started, '2011-02-23 02:32:56',
 1, Resumed FROM ActiveApps;DELETE FROM ActiveApps
 
Error - 03.04.2011 10:33:37 | Computer Name = LUKE | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
 ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2011-04-03 16:33:37', '\device\harddiskvolume1\programme\malwarebytes'
 anti-malware\mbam.exe','1244',0)
 
Error - 03.04.2011 10:40:08 | Computer Name = LUKE | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
 ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2011-04-03 16:40:08', '\device\harddiskvolume1\programme\malwarebytes'
 anti-malware\mbam.exe','1976',0)
 
Error - 03.04.2011 10:45:13 | Computer Name = LUKE | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
 ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2011-04-03 16:45:13', '\device\harddiskvolume1\dokumente
 und einstellungen\all users\anwendungsdaten\malwarebytes\malwarebytes' anti-malware\mbam-setup.exe','3364',0)
 
Error - 03.04.2011 10:52:15 | Computer Name = LUKE | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
 ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2011-04-03 16:52:15', '\device\harddiskvolume1\programme\malwarebytes'
 anti-malware\mbam.exe','3860',0)
 
Error - 03.04.2011 10:53:50 | Computer Name = LUKE | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
 ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2011-04-03 16:53:50', '\device\harddiskvolume1\programme\malwarebytes'
 anti-malware\mbam.exe','3880',0)
 
Error - 03.04.2011 12:44:15 | Computer Name = LUKE | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
 ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2011-04-03 18:44:15', '\device\harddiskvolume1\programme\malwarebytes'
 anti-malware\mbam.exe','5492',0)
 
 
< End of report >

--- --- ---






Danke nochmal

cosinus 03.04.2011 19:40

Gibt es noch weitere Logs von Malwarebytes? Wenn ja bitte alle posten, die in Malwarebytes im Reiter Logdateien sichtbar sind.

el_ukas 03.04.2011 22:29

Danke für eure Hilfe :)

Hier das letzte Log-File mit Fund:



Malwarebytes' Anti-Malware 1.34
Datenbank Version: 1751
Windows 5.1.2600 Service Pack 3

12.02.2009 04:28:39
mbam-log-2009-02-12 (04-28-39).txt

Scan-Methode: Vollständiger Scan (C:\|L:\|)
Durchsuchte Objekte: 147786
Laufzeit: 24 minute(s), 11 second(s)

Infizierte Speicherprozesse: 2
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 10
Infizierte Registrierungswerte: 3
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 3
Infizierte Dateien: 13

Infizierte Speicherprozesse:
C:\Dokumente und Einstellungen\User\Anwendungsdaten\Twain\Twain.exe (Adware.Agent) -> Unloaded process successfully.
C:\Dokumente und Einstellungen\User\Anwendungsdaten\cogad\cogad.exe (Trojan.Agent) -> Unloaded process successfully.

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
HKEY_CLASSES_ROOT\bho_cpv.workhorse (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{63334394-3da3-4b29-a041-03535909d361} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e4a04a1-a24d-45ae-aca4-949778400813} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{15421b84-3488-49a7-ad18-cbf84a3efaf6} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{15421b84-3488-49a7-ad18-cbf84a3efaf6} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{15421b84-3488-49a7-ad18-cbf84a3efaf6} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\bho_cpv.workhorse.1 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\icheck (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\VnrPack (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\freshplay (Trojan.DNSChanger) -> Quarantined and deleted successfully.

Infizierte Registrierungswerte:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\twain (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cogad (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\vnrpack24 (Adware.Agent) -> Quarantined and deleted successfully.

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
C:\Dokumente und Einstellungen\User\Anwendungsdaten\cogad (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Programme\iCheck (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Programme\VnrPack (Adware.Agent) -> Quarantined and deleted successfully.

Infizierte Dateien:
C:\Dokumente und Einstellungen\User\Anwendungsdaten\Twain\Twain.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\Programme\WebShow\WebShow.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Temporary Internet Files\Content.IE5\G11LUTHG\104[1].net (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Temporary Internet Files\Content.IE5\G11LUTHG\155[1].net (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Temporary Internet Files\Content.IE5\GJ9ZRE1C\157[1].net (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Temporary Internet Files\Content.IE5\X1JTXQHI\156[1].net (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Dokumente und Einstellungen\User\Anwendungsdaten\cogad\cogad.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Programme\iCheck\Uninstall.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Programme\VnrPack\dicts.gz (Adware.Agent) -> Quarantined and deleted successfully.
C:\Programme\VnrPack\trgts.gz (Adware.Agent) -> Quarantined and deleted successfully.
C:\Programme\VnrPack\VnrPack24.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Temp\__12.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Temp\__16.tmp (Trojan.Agent) -> Quarantined and deleted successfully.




Gruß

el_ukas

cosinus 04.04.2011 11:27

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)


Code:

:OTL
@Alternate Data Stream - 153 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:DFC5A2B2
@Alternate Data Stream - 112 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:B606BA34
@Alternate Data Stream - 110 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:888AFB86
:Commands
[purity]
[resethosts]
[emptytemp]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

el_ukas 06.04.2011 01:07

Hallo,

hier der OTL-Fix-Log:

All processes killed
========== OTL ==========
ADS C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:DFC5A2B2 deleted successfully.
ADS C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:B606BA34 deleted successfully.
ADS C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:888AFB86 deleted successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 254455 bytes

User: LocalService
->Temp folder emptied: 10254 bytes
->Temporary Internet Files folder emptied: 62033 bytes

User: Luke Firewalker
->Temp folder emptied: 1169064665 bytes
->Temporary Internet Files folder emptied: 65749124 bytes
->Java cache emptied: 3072591 bytes
->FireFox cache emptied: 54882472 bytes
->Flash cache emptied: 52397 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33237 bytes

User: User
->Temp folder emptied: 249362587 bytes
->Temporary Internet Files folder emptied: 777223 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 43930339 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 222509954 bytes
%systemroot% .tmp files removed: 3765107 bytes
%systemroot%\System32 .tmp files removed: 2951 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 491220 bytes
RecycleBin emptied: 19807 bytes

Total Files Cleaned = 1.730,00 mb


OTL by OldTimer - Version 3.2.22.3 log created on 04062011_020107

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...



Vielen Dank nochmal :)

Hat es sich damit erledigt?

Gruß

el_ukas

cosinus 06.04.2011 09:35

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Lade dir ComboFix hier herunter auf deinen Desktop. Benenne es beim Runterladen um in cofi.exe.
http://saved.im/mtm0nzyzmzd5/cofi.jpg
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte cofi.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

el_ukas 06.04.2011 14:41

Hallo,

hier die ComboFix-Log:

Combofix Logfile:
Code:

ComboFix 11-04-05.02 - User 06.04.2011  15:27:57.1.2 - x86
ausgeführt von:: c:\dokumente und einstellungen\Luke Firewalker\Desktop\cofi.exe
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\dokumente und einstellungen\Luke Firewalker\Anwendungsdaten\JuniperExtXP.exe
c:\dokumente und einstellungen\Luke Firewalker\WINDOWS
c:\dokumente und einstellungen\User\Lokale Einstellungen\Anwendungsdaten\lame_enc.dll
c:\dokumente und einstellungen\User\Lokale Einstellungen\Anwendungsdaten\no23xwrapper.dll
c:\dokumente und einstellungen\User\Lokale Einstellungen\Anwendungsdaten\ogg.dll
c:\dokumente und einstellungen\User\Lokale Einstellungen\Anwendungsdaten\vorbis.dll
c:\dokumente und einstellungen\User\Lokale Einstellungen\Anwendungsdaten\vorbisenc.dll
c:\dokumente und einstellungen\User\Lokale Einstellungen\Anwendungsdaten\vorbisfile.dll
c:\dokumente und einstellungen\User\RESIDENTEVIL.EXE
c:\dokumente und einstellungen\User\WINDOWS
.
Infizierte Kopie von c:\windows\system32\ctfmon.exe wurde gefunden und desinfiziert
Kopie von - c:\windows\system32\ctfmon.exe.backup wurde wiederhergestellt
.
.
(((((((((((((((((((((((  Dateien erstellt von 2011-03-06 bis 2011-04-06  ))))))))))))))))))))))))))))))
.
.
2011-04-05 20:34 . 2011-04-05 20:34        --------        d-----w-        c:\programme\PC-WELT
2011-04-05 17:50 . 2011-04-05 17:50        --------        d-----w-        c:\programme\Gemeinsame Dateien\Apple
2011-04-05 17:49 . 2011-04-05 17:50        --------        d-----w-        c:\programme\QuickTime
2011-04-05 17:49 . 2011-04-05 17:49        --------        d-----w-        c:\dokumente und einstellungen\All Users\Anwendungsdaten\Apple Computer
2011-04-05 14:32 . 2011-04-05 14:32        --------        d-----w-        c:\dokumente und einstellungen\All Users\Anwendungsdaten\aVu0oLec
2011-04-05 13:49 . 2011-04-05 13:49        --------        d-----w-        c:\dokumente und einstellungen\User\Anwendungsdaten\Winamp
2011-04-05 13:45 . 2011-04-05 13:45        --------        d-----w-        c:\programme\Winamp Detect
2011-04-03 18:53 . 2011-04-05 19:23        --------        d-----w-        c:\programme\Airfoil
2011-04-03 16:19 . 2011-04-05 14:29        --------        d-----w-        c:\dokumente und einstellungen\Luke Firewalker\Anwendungsdaten\Winamp
2011-04-03 15:51 . 2011-04-03 15:53        --------        d-----w-        c:\programme\PC Beschleunigen
2011-04-03 15:51 . 2011-04-03 15:51        --------        d-----w-        c:\dokumente und einstellungen\User\Lokale Einstellungen\Anwendungsdaten\OpenCandy
2011-04-03 15:51 . 2011-03-04 19:44        59888        ------w-        c:\windows\system32\pxwma.dll
2011-04-03 15:51 . 2011-04-03 15:51        --------        d-----w-        c:\dokumente und einstellungen\User\Anwendungsdaten\OpenCandy
2011-04-03 15:40 . 2011-04-05 13:45        --------        d-----w-        c:\programme\Winamp
2011-04-03 14:21 . 2011-04-03 14:21        --------        d-sh--w-        c:\windows\system32\config\systemprofile\IETldCache
2011-04-03 13:23 . 2011-04-03 13:23        --------        d-sh--w-        c:\dokumente und einstellungen\User\IECompatCache
2011-04-03 13:12 . 2011-04-03 13:12        --------        d-----w-        c:\programme\CCleaner
2011-04-03 10:28 . 2011-03-18 17:56        142296        ----a-w-        c:\programme\Mozilla Firefox\components\browsercomps.dll
2011-04-03 10:28 . 2011-03-18 17:56        781272        ----a-w-        c:\programme\Mozilla Firefox\mozsqlite3.dll
2011-04-03 10:28 . 2011-03-18 17:56        728024        ----a-w-        c:\programme\Mozilla Firefox\libGLESv2.dll
2011-04-03 10:28 . 2011-03-18 17:56        719832        ----a-w-        c:\programme\Mozilla Firefox\mozcpp19.dll
2011-04-03 10:28 . 2011-03-18 17:56        1975768        ----a-w-        c:\programme\Mozilla Firefox\D3DCompiler_42.dll
2011-04-03 10:28 . 2011-03-18 17:56        1893336        ----a-w-        c:\programme\Mozilla Firefox\d3dx9_42.dll
2011-04-03 10:28 . 2011-03-18 17:56        1874904        ----a-w-        c:\programme\Mozilla Firefox\mozjs.dll
2011-04-03 10:28 . 2011-03-18 17:56        16856        ----a-w-        c:\programme\Mozilla Firefox\plugin-container.exe
2011-04-03 10:28 . 2011-03-18 17:56        15832        ----a-w-        c:\programme\Mozilla Firefox\mozalloc.dll
2011-04-03 10:28 . 2011-03-18 17:56        142296        ----a-w-        c:\programme\Mozilla Firefox\libEGL.dll
2011-03-31 23:53 . 2011-03-31 23:53        --------        d-----w-        c:\dokumente und einstellungen\User\Schachspiele
2011-03-29 16:07 . 2011-03-29 16:11        --------        d-----w-        C:\pebuilder-stick
2011-03-29 16:06 . 2011-03-29 16:15        --------        d-----w-        C:\pebuilder
2011-03-29 14:03 . 2011-03-29 14:03        --------        d-----w-        c:\programme\LogMeIn Hamachi
2011-03-24 16:45 . 2011-03-24 16:45        --------        d-----w-        C:\usbdos
2011-03-24 16:43 . 2011-03-24 16:43        --------        d-----w-        C:\DriveKey
2011-03-17 19:57 . 2011-03-17 19:57        12800        ----a-w-        c:\programme\Mozilla Firefox\plugins\npwachk.dll
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-18 10:43 . 2010-07-06 12:38        137656        ----a-w-        c:\windows\system32\drivers\avipbb.sys
2011-03-04 19:44 . 2009-01-02 21:18        45648        ------w-        c:\windows\system32\drivers\PxHelp20.sys
2011-03-04 19:44 . 2009-01-02 21:18        133616        ------w-        c:\windows\system32\pxafs.dll
2011-03-04 19:44 . 2009-01-02 21:18        126448        ------w-        c:\windows\system32\pxinsi64.exe
2011-03-04 19:44 . 2009-01-02 21:18        123888        ------w-        c:\windows\system32\pxcpyi64.exe
2011-02-09 13:53 . 2008-04-14 05:52        270848        ----a-w-        c:\windows\system32\sbe.dll
2011-02-09 13:53 . 2008-04-14 05:52        186880        ----a-w-        c:\windows\system32\encdec.dll
2011-02-02 07:58 . 2009-01-02 13:53        2067456        ----a-w-        c:\windows\system32\mstscax.dll
2011-01-27 11:57 . 2009-01-02 13:53        677888        ----a-w-        c:\windows\system32\mstsc.exe
2011-01-21 14:44 . 2008-04-14 05:52        440832        ----a-w-        c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2008-04-14 05:50        290048        ----a-w-        c:\windows\system32\atmfd.dll
2011-03-18 17:56 . 2011-04-03 10:28        142296        ----a-w-        c:\programme\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\programme\QuickTime\QTTask.exe" [2010-11-29 421888]
"Google Update"="c:\dokumente und einstellungen\Luke Firewalker\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe" [2009-02-06 133104]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programme\Gemeinsame Dateien\Nero\Lib\NMBgMonitor.exe" [2007-09-20 202024]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\programme\Synaptics\SynTP\SynTPEnh.exe" [2007-12-06 1024000]
"TouchPadHotKey"="c:\programme\FSC\TouchPad HotKey Utility\TouchPad_HotKey.exe" [2007-08-13 364544]
"RTHDCPL"="RTHDCPL.EXE" [2009-04-30 17881088]
"SiSPower"="SiSPower.dll" [2008-06-27 53248]
"avgnt"="c:\programme\Avira\AntiVir Desktop\avgnt.exe" [2010-11-02 281768]
"QuickTime Task"="c:\programme\QuickTime\QTTask.exe" [2010-11-29 421888]
"AirPort Base Station Agent"="c:\programme\AirPort\APAgent.exe" [2009-11-11 771360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\dokumente und einstellungen\All Users\Startmen\Programme\Autostart\
Utility Tray.lnk - c:\windows\system32\sistray.exe [2009-1-2 262144]
WirelessSelector.lnk - c:\programme\FSC\Wireless Utility\WirelessSelector.exe [2009-1-2 650752]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AirPort Base Station Agent]
2009-11-11 14:17        771360        ----a-w-        c:\programme\AirPort\APAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2007-09-20 14:35        202024        ----a-w-        c:\programme\Gemeinsame Dateien\Nero\Lib\NMBgMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2008-12-29 10:40        687560        ----a-w-        c:\programme\DAEMON Tools Lite\daemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashPlayerUpdate]
2009-02-03 02:15        240544        ----a-w-        c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-02-06 02:53        133104        ----atw-        c:\dokumente und einstellungen\Luke Firewalker\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
2011-03-28 13:41        1910152        ----a-w-        c:\programme\LogMeIn Hamachi\hamachi-2-ui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
2007-09-20 08:51        1836328        ----a-w-        c:\programme\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 14:57        153136        ----a-w-        c:\programme\Gemeinsame Dateien\Nero\Lib\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\programme\QuickTime\QTTask.exe" -atboottime
"SunJavaUpdateSched"="c:\programme\Java\jre6\bin\jusched.exe"
"BluetoothAuthenticationAgent"=rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
"CherryKeyMan"="c:\programme\Cherry\KeyMan\KeyMan.exe"
"LogMeIn Hamachi Ui"="c:\programme\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programme\\uTorrent\\uTorrent.exe"=
"c:\\Programme\\SoulseekNS\\slsk.exe"=
"c:\\Programme\\TmNationsForever\\TmForever.exe"=
"c:\\Programme\\Quake III Arena\\quake3.exe"=
"c:\\Programme\\Valve\\hl.exe"=
"c:\\Programme\\Valve\\hlds.exe"=
"c:\\Programme\\Miranda IM\\miranda32.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Programme\\Microsoft Games\\Age of Empires II\\age2_x1\\age2_x1.icd"=
"c:\\Programme\\Microsoft Games\\Age of Empires II\\EMPIRES2.ICD"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Programme\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programme\\Java\\jre6\\launch4j-tmp\\JDownloader.exe"=
"c:\\Programme\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Programme\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Programme\\eMule\\emule.exe"=
"c:\\Programme\\Winamp\\winamp.exe"=
"c:\\Programme\\Bonjour\\mDNSResponder.exe"=
"c:\\Programme\\AirPort\\APAgent.exe"=
"c:\\Programme\\AirPort\\APUtil.exe"=
"c:\\Programme\\Airfoil\\Airfoil.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:UDP"= 5353:UDP:Bonjour
"20000:TCP"= 20000:TCP:miranda1
"20001:TCP"= 20001:TCP:m2
"20002:TCP"= 20002:TCP:m3
"20000:UDP"= 20000:UDP:m4
"20001:UDP"= 20001:UDP:m5
"20002:UDP"= 20002:UDP:m6
"3689:TCP"= 3689:TCP:RemoteSpeaker_Winamp
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [25.10.2009 13:59 64160]
R0 pxscan;pxscan;c:\windows\system32\drivers\pxscan.sys [06.07.2010 14:52 22024]
R0 pxsec;pxsec;c:\windows\system32\drivers\pxsec.sys [06.07.2010 14:52 27656]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [18.01.2009 00:02 717296]
R2 AntiVirSchedulerService;Avira AntiVir Planer;c:\programme\Avira\AntiVir Desktop\sched.exe [06.07.2010 14:38 135336]
R2 CSIScanner;CSIScanner;c:\programme\Prevx\prevx.exe [06.07.2010 14:52 4368952]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\programme\LogMeIn Hamachi\hamachi-2.exe [28.03.2011 15:41 1242504]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\programme\Lavasoft\Ad-Aware\AAWService.exe [03.07.2009 16:49 1029456]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\programme\McAfee\SiteAdvisor\McSACore.exe [02.02.2009 02:48 88176]
R3 Ch2kPS2;Cherry PS/2 Tastatur Treiber (CDI);c:\windows\system32\drivers\Ch2kPS2.sys [24.01.2008 10:41 130560]
R3 KeyScrambler;KeyScrambler;c:\windows\system32\drivers\keyscrambler.sys [25.05.2009 13:30 113896]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [13.05.2009 20:53 1684736]
S3 Camavb;%USB\VID_04C8&PID_0720.DeviceDesc%;c:\windows\system32\drivers\Camavb.sys [04.01.2009 18:01 72832]
S3 Ch2kPS2M;Cherry PS/2 Maus Treiber (CDI);c:\windows\system32\drivers\Ch2kPS2M.sys [10.01.2007 14:58 54272]
S3 Ch2kUSB;Cherry USB Treiber für CDI;c:\windows\system32\drivers\Ch2kUSB.sys [23.08.2007 08:29 112512]
S3 Ch2kUSBM;Cherry USB Maus Treiber für CDI;c:\windows\system32\drivers\Ch2kUSBm.sys [07.03.2007 09:46 63616]
S3 Cherry Device Interface;Cherry Device Interface;c:\programme\Cherry\CDI\cdi.exe [04.12.2007 13:03 585774]
S3 TrmbTS;TrmbTS;c:\windows\system32\drivers\TrmbTS.sys [09.11.2009 12:09 29184]
S3 TRMUSB5K;Trimble USB GPS Driver;c:\windows\system32\drivers\TRMUSB5K.SYS [09.11.2009 12:10 9881]
S3 wip0204;Wippien Network Adapter 2.4;c:\windows\system32\drivers\wip0204.sys [07.08.2010 18:19 23480]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
UxTuneUp
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{48164576-3ca5-11df-bcba-001e330b0a14}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{57d3b8f4-798b-11df-bd1f-001e330b0a14}]
\Shell\AutoRun\command - G:\Menu.exe
.
Inhalt des "geplante Tasks" Ordners
.
2011-04-06 c:\windows\Tasks\1-Klick-Wartung.job
- c:\programme\TuneUp Utilities 2009\OneClickStarter.exe [2009-11-16 11:45]
.
2011-04-03 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\programme\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 11:59]
.
2011-04-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programme\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
2011-04-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-746137067-1645522239-1177238915-1005Core.job
- c:\dokumente und einstellungen\Luke Firewalker\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe [2009-02-06 02:53]
.
2011-04-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-746137067-1645522239-1177238915-1005UA.job
- c:\dokumente und einstellungen\Luke Firewalker\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe [2009-02-06 02:53]
.
.
------- Zusätzlicher Suchlauf -------
.
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - {E601996F-E400-41CA-804B-CD6373A7EEE2} -
Trusted Zone: ebay.de\www
FF - ProfilePath - c:\dokumente und einstellungen\Luke Firewalker\Anwendungsdaten\Mozilla\Firefox\Profiles\wdp3x132.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: keyword.URL - hxxp://de.search.yahoo.com/search?fr=mcafee&p=
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
BHO-{E601996F-E400-41CA-804B-CD6373A7EEE2} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2011-04-06 15:33
Windows 5.1.2600 Service Pack 3 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•6~*]
"7040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'explorer.exe'(3856)
c:\progra~1\mcafee\SITEAD~1\saHook.dll
c:\windows\system32\webcheck.dll
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\programme\Avira\AntiVir Desktop\avguard.exe
c:\programme\Bonjour\mDNSResponder.exe
c:\programme\Java\jre6\bin\jqs.exe
c:\programme\Avira\AntiVir Desktop\avshadow.exe
c:\programme\Nero\Nero8\Nero BackItUp\NBService.exe
c:\programme\CDBurnerXP\NMSAccessU.exe
c:\windows\System32\TUProgSt.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\rundll32.exe
c:\programme\Gemeinsame Dateien\Nero\Lib\NMIndexingService.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\programme\Gemeinsame Dateien\Nero\Lib\NMIndexStoreSvr.exe
c:\programme\Lavasoft\Ad-Aware\AAWTray.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2011-04-06  15:38:27 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2011-04-06 13:38
.
Vor Suchlauf: 7.554.555.904 Bytes frei
Nach Suchlauf: 7.586.877.440 Bytes frei
.
WindowsXP-KB310994-SP2-Home-BootDisk-DEU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 586A196A9090C1ADB6050846BAE8FE05

--- --- ---



Ich danke nochmals für deine Hilfe :daumenhoc

Gruß

el_ukas

cosinus 06.04.2011 15:31

Combofix - Scripten

1. Starte das Notepad (Start / Ausführen / notepad[Enter])

2. Jetzt füge mit copy/paste den ganzen Inhalt der untenstehenden Codebox in das Notepad Fenster ein.

Code:

Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:UDP"=-
"20000:TCP"=-
"20001:TCP"=-
"20002:TCP"=-
"20000:UDP"=-
"20001:UDP"=-
"20002:UDP"=-
"3689:TCP"=-

3. Speichere im Notepad als CFScript.txt auf dem Desktop.

4. Deaktivere den Guard Deines Antivirenprogramms und eine eventuell vorhandene Software Firewall.
(Auch Guards von Ad-, Spyware Programmen und den Tea Timer (wenn vorhanden) !)

5. Dann ziehe die CFScript.txt auf die cofi.exe, so wie es im unteren Bild zu sehen ist. Damit wird Combofix neu gestartet.

http://users.pandora.be/bluepatchy/m...s/CFScript.gif

6. Nach dem Neustart (es wird gefragt ob Du neustarten willst), poste bitte die folgenden Log Dateien:
Combofix.txt

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

el_ukas 07.04.2011 09:51

Hey cosinus,

danke für deine Hilfe...finde ich echt super :daumenhoc

Hier das ComboFix-Log:

Combofix Logfile:
Code:

ComboFix 11-04-06.03 - Luke Firewalker 07.04.2011  10:41:21.2.2 - x86
Microsoft Windows XP Home Edition  5.1.2600.3.1252.49.1031.18.1981.1448 [GMT 2:00]
ausgeführt von:: c:\dokumente und einstellungen\Luke Firewalker\Desktop\cofi.exe
Benutzte Befehlsschalter :: c:\dokumente und einstellungen\Luke Firewalker\Desktop\CFScript.txt
AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
.
(((((((((((((((((((((((  Dateien erstellt von 2011-03-07 bis 2011-04-07  ))))))))))))))))))))))))))))))
.
.
2011-04-06 13:25 . 2011-04-06 13:38        --------        d-----w-        C:\cofi
2011-04-05 20:41 . 2011-04-05 20:54        --------        d-----w-        c:\dokumente und einstellungen\Default User\Anwendungsdaten\Winamp
2011-04-05 20:36 . 2011-04-05 20:36        --------        d-----w-        c:\dokumente und einstellungen\Default User\Lokale Einstellungen\Anwendungsdaten\Rogue_Amoeba
2011-04-05 20:34 . 2011-04-05 20:34        --------        d-----w-        c:\programme\PC-WELT
2011-04-05 17:50 . 2011-04-05 17:50        --------        d-----w-        c:\programme\Gemeinsame Dateien\Apple
2011-04-05 17:49 . 2011-04-05 17:50        --------        d-----w-        c:\programme\QuickTime
2011-04-05 17:49 . 2011-04-05 17:49        --------        d-----w-        c:\dokumente und einstellungen\All Users\Anwendungsdaten\Apple Computer
2011-04-05 14:32 . 2011-04-05 14:32        --------        d-----w-        c:\dokumente und einstellungen\All Users\Anwendungsdaten\aVu0oLec
2011-04-05 13:49 . 2011-04-05 13:49        --------        d-----w-        c:\dokumente und einstellungen\User\Anwendungsdaten\Winamp
2011-04-05 13:45 . 2011-04-05 13:45        --------        d-----w-        c:\programme\Winamp Detect
2011-04-03 18:53 . 2011-04-05 19:23        --------        d-----w-        c:\programme\Airfoil
2011-04-03 16:19 . 2011-04-05 14:29        --------        d-----w-        c:\dokumente und einstellungen\Luke Firewalker\Anwendungsdaten\Winamp
2011-04-03 15:51 . 2011-04-03 15:53        --------        d-----w-        c:\programme\PC Beschleunigen
2011-04-03 15:51 . 2011-04-03 15:51        --------        d-----w-        c:\dokumente und einstellungen\User\Lokale Einstellungen\Anwendungsdaten\OpenCandy
2011-04-03 15:51 . 2011-03-04 19:44        59888        ------w-        c:\windows\system32\pxwma.dll
2011-04-03 15:51 . 2011-04-03 15:51        --------        d-----w-        c:\dokumente und einstellungen\User\Anwendungsdaten\OpenCandy
2011-04-03 15:40 . 2011-04-05 13:45        --------        d-----w-        c:\programme\Winamp
2011-04-03 14:21 . 2011-04-03 14:21        --------        d-sh--w-        c:\windows\system32\config\systemprofile\IETldCache
2011-04-03 13:23 . 2011-04-03 13:23        --------        d-sh--w-        c:\dokumente und einstellungen\User\IECompatCache
2011-04-03 13:12 . 2011-04-03 13:12        --------        d-----w-        c:\programme\CCleaner
2011-04-03 10:28 . 2011-03-18 17:56        142296        ----a-w-        c:\programme\Mozilla Firefox\components\browsercomps.dll
2011-04-03 10:28 . 2011-03-18 17:56        781272        ----a-w-        c:\programme\Mozilla Firefox\mozsqlite3.dll
2011-04-03 10:28 . 2011-03-18 17:56        728024        ----a-w-        c:\programme\Mozilla Firefox\libGLESv2.dll
2011-04-03 10:28 . 2011-03-18 17:56        719832        ----a-w-        c:\programme\Mozilla Firefox\mozcpp19.dll
2011-04-03 10:28 . 2011-03-18 17:56        1975768        ----a-w-        c:\programme\Mozilla Firefox\D3DCompiler_42.dll
2011-04-03 10:28 . 2011-03-18 17:56        1893336        ----a-w-        c:\programme\Mozilla Firefox\d3dx9_42.dll
2011-04-03 10:28 . 2011-03-18 17:56        1874904        ----a-w-        c:\programme\Mozilla Firefox\mozjs.dll
2011-04-03 10:28 . 2011-03-18 17:56        16856        ----a-w-        c:\programme\Mozilla Firefox\plugin-container.exe
2011-04-03 10:28 . 2011-03-18 17:56        15832        ----a-w-        c:\programme\Mozilla Firefox\mozalloc.dll
2011-04-03 10:28 . 2011-03-18 17:56        142296        ----a-w-        c:\programme\Mozilla Firefox\libEGL.dll
2011-03-31 23:53 . 2011-03-31 23:53        --------        d-----w-        c:\dokumente und einstellungen\User\Schachspiele
2011-03-29 16:07 . 2011-03-29 16:11        --------        d-----w-        C:\pebuilder-stick
2011-03-29 16:06 . 2011-03-29 16:15        --------        d-----w-        C:\pebuilder
2011-03-29 14:03 . 2011-03-29 14:03        --------        d-----w-        c:\programme\LogMeIn Hamachi
2011-03-24 16:45 . 2011-03-24 16:45        --------        d-----w-        C:\usbdos
2011-03-24 16:43 . 2011-03-24 16:43        --------        d-----w-        C:\DriveKey
2011-03-17 19:57 . 2011-03-17 19:57        12800        ----a-w-        c:\programme\Mozilla Firefox\plugins\npwachk.dll
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-18 10:43 . 2010-07-06 12:38        137656        ----a-w-        c:\windows\system32\drivers\avipbb.sys
2011-03-04 19:44 . 2009-01-02 21:18        45648        ------w-        c:\windows\system32\drivers\PxHelp20.sys
2011-03-04 19:44 . 2009-01-02 21:18        133616        ------w-        c:\windows\system32\pxafs.dll
2011-03-04 19:44 . 2009-01-02 21:18        126448        ------w-        c:\windows\system32\pxinsi64.exe
2011-03-04 19:44 . 2009-01-02 21:18        123888        ------w-        c:\windows\system32\pxcpyi64.exe
2011-02-09 13:53 . 2008-04-14 05:52        270848        ----a-w-        c:\windows\system32\sbe.dll
2011-02-09 13:53 . 2008-04-14 05:52        186880        ----a-w-        c:\windows\system32\encdec.dll
2011-02-02 07:58 . 2009-01-02 13:53        2067456        ----a-w-        c:\windows\system32\mstscax.dll
2011-01-27 11:57 . 2009-01-02 13:53        677888        ----a-w-        c:\windows\system32\mstsc.exe
2011-01-21 14:44 . 2008-04-14 05:52        440832        ----a-w-        c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2008-04-14 05:50        290048        ----a-w-        c:\windows\system32\atmfd.dll
2011-03-18 17:56 . 2011-04-03 10:28        142296        ----a-w-        c:\programme\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\programme\QuickTime\QTTask.exe" [2010-11-29 421888]
"Google Update"="c:\dokumente und einstellungen\Luke Firewalker\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe" [2009-02-06 133104]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programme\Gemeinsame Dateien\Nero\Lib\NMBgMonitor.exe" [2007-09-20 202024]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\programme\Synaptics\SynTP\SynTPEnh.exe" [2007-12-06 1024000]
"TouchPadHotKey"="c:\programme\FSC\TouchPad HotKey Utility\TouchPad_HotKey.exe" [2007-08-13 364544]
"RTHDCPL"="RTHDCPL.EXE" [2009-04-30 17881088]
"SiSPower"="SiSPower.dll" [2008-06-27 53248]
"avgnt"="c:\programme\Avira\AntiVir Desktop\avgnt.exe" [2010-11-02 281768]
"QuickTime Task"="c:\programme\QuickTime\QTTask.exe" [2010-11-29 421888]
"AirPort Base Station Agent"="c:\programme\AirPort\APAgent.exe" [2009-11-11 771360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\dokumente und einstellungen\All Users\Startmen\Programme\Autostart\
Utility Tray.lnk - c:\windows\system32\sistray.exe [2009-1-2 262144]
WirelessSelector.lnk - c:\programme\FSC\Wireless Utility\WirelessSelector.exe [2009-1-2 650752]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AirPort Base Station Agent]
2009-11-11 14:17        771360        ----a-w-        c:\programme\AirPort\APAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2007-09-20 14:35        202024        ----a-w-        c:\programme\Gemeinsame Dateien\Nero\Lib\NMBgMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2008-12-29 10:40        687560        ----a-w-        c:\programme\DAEMON Tools Lite\daemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashPlayerUpdate]
2009-02-03 02:15        240544        ----a-w-        c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-02-06 02:53        133104        ----atw-        c:\dokumente und einstellungen\Luke Firewalker\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
2011-03-28 13:41        1910152        ----a-w-        c:\programme\LogMeIn Hamachi\hamachi-2-ui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
2007-09-20 08:51        1836328        ----a-w-        c:\programme\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 14:57        153136        ----a-w-        c:\programme\Gemeinsame Dateien\Nero\Lib\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\programme\QuickTime\QTTask.exe" -atboottime
"SunJavaUpdateSched"="c:\programme\Java\jre6\bin\jusched.exe"
"BluetoothAuthenticationAgent"=rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
"CherryKeyMan"="c:\programme\Cherry\KeyMan\KeyMan.exe"
"LogMeIn Hamachi Ui"="c:\programme\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programme\\uTorrent\\uTorrent.exe"=
"c:\\Programme\\SoulseekNS\\slsk.exe"=
"c:\\Programme\\TmNationsForever\\TmForever.exe"=
"c:\\Programme\\Quake III Arena\\quake3.exe"=
"c:\\Programme\\Valve\\hl.exe"=
"c:\\Programme\\Valve\\hlds.exe"=
"c:\\Programme\\Miranda IM\\miranda32.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Programme\\Microsoft Games\\Age of Empires II\\age2_x1\\age2_x1.icd"=
"c:\\Programme\\Microsoft Games\\Age of Empires II\\EMPIRES2.ICD"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Programme\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programme\\Java\\jre6\\launch4j-tmp\\JDownloader.exe"=
"c:\\Programme\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Programme\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Programme\\eMule\\emule.exe"=
"c:\\Programme\\Winamp\\winamp.exe"=
"c:\\Programme\\Bonjour\\mDNSResponder.exe"=
"c:\\Programme\\AirPort\\APAgent.exe"=
"c:\\Programme\\AirPort\\APUtil.exe"=
"c:\\Programme\\Airfoil\\Airfoil.exe"=
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [25.10.2009 13:59 64160]
R0 pxscan;pxscan;c:\windows\system32\drivers\pxscan.sys [06.07.2010 14:52 22024]
R0 pxsec;pxsec;c:\windows\system32\drivers\pxsec.sys [06.07.2010 14:52 27656]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [18.01.2009 00:02 717296]
R2 AntiVirSchedulerService;Avira AntiVir Planer;c:\programme\Avira\AntiVir Desktop\sched.exe [06.07.2010 14:38 135336]
R2 CSIScanner;CSIScanner;c:\programme\Prevx\prevx.exe [06.07.2010 14:52 4368952]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\programme\LogMeIn Hamachi\hamachi-2.exe [28.03.2011 15:41 1242504]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\programme\Lavasoft\Ad-Aware\AAWService.exe [03.07.2009 16:49 1029456]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\programme\McAfee\SiteAdvisor\McSACore.exe [02.02.2009 02:48 88176]
R3 Ch2kPS2;Cherry PS/2 Tastatur Treiber (CDI);c:\windows\system32\drivers\Ch2kPS2.sys [24.01.2008 10:41 130560]
R3 KeyScrambler;KeyScrambler;c:\windows\system32\drivers\keyscrambler.sys [25.05.2009 13:30 113896]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [13.05.2009 20:53 1684736]
S3 Camavb;%USB\VID_04C8&PID_0720.DeviceDesc%;c:\windows\system32\drivers\Camavb.sys [04.01.2009 18:01 72832]
S3 Ch2kPS2M;Cherry PS/2 Maus Treiber (CDI);c:\windows\system32\drivers\Ch2kPS2M.sys [10.01.2007 14:58 54272]
S3 Ch2kUSB;Cherry USB Treiber für CDI;c:\windows\system32\drivers\Ch2kUSB.sys [23.08.2007 08:29 112512]
S3 Ch2kUSBM;Cherry USB Maus Treiber für CDI;c:\windows\system32\drivers\Ch2kUSBm.sys [07.03.2007 09:46 63616]
S3 Cherry Device Interface;Cherry Device Interface;c:\programme\Cherry\CDI\cdi.exe [04.12.2007 13:03 585774]
S3 TrmbTS;TrmbTS;c:\windows\system32\drivers\TrmbTS.sys [09.11.2009 12:09 29184]
S3 TRMUSB5K;Trimble USB GPS Driver;c:\windows\system32\drivers\TRMUSB5K.SYS [09.11.2009 12:10 9881]
S3 wip0204;Wippien Network Adapter 2.4;c:\windows\system32\drivers\wip0204.sys [07.08.2010 18:19 23480]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
UxTuneUp
.
Inhalt des "geplante Tasks" Ordners
.
2011-04-07 c:\windows\Tasks\1-Klick-Wartung.job
- c:\programme\TuneUp Utilities 2009\OneClickStarter.exe [2009-11-16 11:45]
.
2011-04-03 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\programme\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 11:59]
.
2011-04-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programme\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
2011-04-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-746137067-1645522239-1177238915-1005Core.job
- c:\dokumente und einstellungen\Luke Firewalker\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe [2009-02-06 02:53]
.
2011-04-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-746137067-1645522239-1177238915-1005UA.job
- c:\dokumente und einstellungen\Luke Firewalker\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe [2009-02-06 02:53]
.
.
------- Zusätzlicher Suchlauf -------
.
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - {E601996F-E400-41CA-804B-CD6373A7EEE2} -
Trusted Zone: ebay.de\www
FF - ProfilePath - c:\dokumente und einstellungen\Luke Firewalker\Anwendungsdaten\Mozilla\Firefox\Profiles\wdp3x132.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: keyword.URL - hxxp://de.search.yahoo.com/search?fr=mcafee&p=
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2011-04-07 10:46
Windows 5.1.2600 Service Pack 3 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•6~*]
"7040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'explorer.exe'(3116)
c:\progra~1\mcafee\SITEAD~1\saHook.dll
c:\windows\system32\webcheck.dll
.
Zeit der Fertigstellung: 2011-04-07  10:47:47
ComboFix-quarantined-files.txt  2011-04-07 08:47
ComboFix2.txt  2011-04-06 13:38
.
Vor Suchlauf: 7.544.979.456 Bytes frei
Nach Suchlauf: 7.532.412.928 Bytes frei
.
- - End Of File - - 7CD686B159BA040AA3C62A148B6C3F1F

--- --- ---


Gruß

el_ukas

cosinus 07.04.2011 10:14

Bitte nun dieses Tool von Kaspersky ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html

el_ukas 07.04.2011 13:55

Hier die Log: (ich glaube er hat einen Thread gefunden und in dann in die quarantäne verschoben system32\driver\spdt.sys




2011/04/07 14:51:12.0312 5904 TDSS rootkit removing tool 2.4.21.0 Mar 10 2011 12:26:28
2011/04/07 14:51:12.0765 5904 ================================================================================
2011/04/07 14:51:12.0765 5904 SystemInfo:
2011/04/07 14:51:12.0765 5904
2011/04/07 14:51:12.0765 5904 OS Version: 5.1.2600 ServicePack: 3.0
2011/04/07 14:51:12.0765 5904 Product type: Workstation
2011/04/07 14:51:12.0765 5904 ComputerName: LUKE
2011/04/07 14:51:12.0765 5904 UserName: Luke Firewalker
2011/04/07 14:51:12.0765 5904 Windows directory: C:\WINDOWS
2011/04/07 14:51:12.0765 5904 System windows directory: C:\WINDOWS
2011/04/07 14:51:12.0765 5904 Processor architecture: Intel x86
2011/04/07 14:51:12.0765 5904 Number of processors: 2
2011/04/07 14:51:12.0765 5904 Page size: 0x1000
2011/04/07 14:51:12.0765 5904 Boot type: Normal boot
2011/04/07 14:51:12.0765 5904 ================================================================================
2011/04/07 14:51:13.0296 5904 Initialize success
2011/04/07 14:51:20.0125 3884 ================================================================================
2011/04/07 14:51:20.0125 3884 Scan started
2011/04/07 14:51:20.0125 3884 Mode: Manual;
2011/04/07 14:51:20.0125 3884 ================================================================================
2011/04/07 14:51:20.0781 3884 ACPI (ac407f1a62c3a300b4f2b5a9f1d55b2c) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2011/04/07 14:51:20.0812 3884 ACPIEC (9e1ca3160dafb159ca14f83b1e317f75) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
2011/04/07 14:51:20.0875 3884 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2011/04/07 14:51:20.0937 3884 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys
2011/04/07 14:51:21.0140 3884 Ambfilt (f6af59d6eee5e1c304f7f73706ad11d8) C:\WINDOWS\system32\drivers\Ambfilt.sys
2011/04/07 14:51:21.0296 3884 AR5211 (9108f38c07f4953ea4ee89243e787cad) C:\WINDOWS\system32\DRIVERS\ar5211.sys
2011/04/07 14:51:21.0453 3884 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2011/04/07 14:51:21.0484 3884 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2011/04/07 14:51:21.0546 3884 atksgt (6e996cf8459a2594e0e9609d0e34d41f) C:\WINDOWS\system32\DRIVERS\atksgt.sys
2011/04/07 14:51:21.0640 3884 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2011/04/07 14:51:21.0687 3884 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2011/04/07 14:51:21.0765 3884 avgio (0b497c79824f8e1bf22fa6aacd3de3a0) C:\Programme\Avira\AntiVir Desktop\avgio.sys
2011/04/07 14:51:21.0843 3884 avgntflt (47b879406246ffdced59e18d331a0e7d) C:\WINDOWS\system32\DRIVERS\avgntflt.sys
2011/04/07 14:51:21.0875 3884 avipbb (5fedef54757b34fb611b9ec8fb399364) C:\WINDOWS\system32\DRIVERS\avipbb.sys
2011/04/07 14:51:21.0937 3884 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2011/04/07 14:51:21.0984 3884 BthEnum (b279426e3c0c344893ed78a613a73bde) C:\WINDOWS\system32\DRIVERS\BthEnum.sys
2011/04/07 14:51:22.0046 3884 BthPan (80602b8746d3738f5886ce3d67ef06b6) C:\WINDOWS\system32\DRIVERS\bthpan.sys
2011/04/07 14:51:22.0125 3884 BTHPORT (592e1cedbe314d0ef184dc6f46141e76) C:\WINDOWS\system32\Drivers\BTHport.sys
2011/04/07 14:51:22.0203 3884 BTHUSB (61364cd71ef63b0f038b7e9df00f1efa) C:\WINDOWS\system32\Drivers\BTHUSB.sys
2011/04/07 14:51:22.0265 3884 Camavb (e86cacc83bf82fd7e1a15122c5a75bc3) C:\WINDOWS\system32\Drivers\Camavb.sys
2011/04/07 14:51:22.0515 3884 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2011/04/07 14:51:22.0546 3884 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
2011/04/07 14:51:22.0609 3884 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2011/04/07 14:51:22.0640 3884 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2011/04/07 14:51:22.0718 3884 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2011/04/07 14:51:22.0765 3884 Ch2kPS2 (970dddebaa177ad1f738a24c8d9c0735) C:\WINDOWS\system32\DRIVERS\Ch2kPS2.sys
2011/04/07 14:51:22.0812 3884 Ch2kPS2M (7a0c65d3977c4ab79459685aeafaa9fb) C:\WINDOWS\system32\DRIVERS\Ch2kPS2M.sys
2011/04/07 14:51:22.0843 3884 Ch2kUSB (6bb54c8ab2ff2406c08157052cae793c) C:\WINDOWS\system32\drivers\Ch2kUSB.sys
2011/04/07 14:51:22.0890 3884 Ch2kUSBM (75eefef268189a530a22cec6b3331f9c) C:\WINDOWS\system32\drivers\Ch2kUSBm.sys
2011/04/07 14:51:23.0015 3884 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
2011/04/07 14:51:23.0046 3884 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
2011/04/07 14:51:23.0171 3884 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
2011/04/07 14:51:23.0234 3884 dmboot (0dcfc8395a99fecbb1ef771cec7fe4ea) C:\WINDOWS\system32\drivers\dmboot.sys
2011/04/07 14:51:23.0312 3884 dmio (53720ab12b48719d00e327da470a619a) C:\WINDOWS\system32\drivers\dmio.sys
2011/04/07 14:51:23.0343 3884 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2011/04/07 14:51:23.0406 3884 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2011/04/07 14:51:23.0437 3884 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2011/04/07 14:51:23.0500 3884 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2011/04/07 14:51:23.0578 3884 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
2011/04/07 14:51:23.0593 3884 Fips (b0678a548587c5f1967b0d70bacad6c1) C:\WINDOWS\system32\drivers\Fips.sys
2011/04/07 14:51:23.0625 3884 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
2011/04/07 14:51:23.0671 3884 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
2011/04/07 14:51:23.0703 3884 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2011/04/07 14:51:23.0718 3884 Ftdisk (8f1955ce42e1484714b542f341647778) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2011/04/07 14:51:23.0750 3884 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2011/04/07 14:51:23.0843 3884 hamachi (833051c6c6c42117191935f734cfbd97) C:\WINDOWS\system32\DRIVERS\hamachi.sys
2011/04/07 14:51:23.0937 3884 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
2011/04/07 14:51:23.0968 3884 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2011/04/07 14:51:24.0078 3884 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
2011/04/07 14:51:24.0203 3884 i8042prt (e283b97cfbeb86c1d86baed5f7846a92) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2011/04/07 14:51:24.0250 3884 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
2011/04/07 14:51:24.0468 3884 IntcAzAudAddService (a79be85c034d6199e07adafe64065848) C:\WINDOWS\system32\drivers\RtkHDAud.sys
2011/04/07 14:51:24.0671 3884 intelppm (4c7d2750158ed6e7ad642d97bffae351) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2011/04/07 14:51:24.0703 3884 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
2011/04/07 14:51:24.0750 3884 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2011/04/07 14:51:24.0765 3884 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2011/04/07 14:51:24.0796 3884 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2011/04/07 14:51:24.0875 3884 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2011/04/07 14:51:24.0921 3884 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2011/04/07 14:51:24.0984 3884 isapnp (6dfb88f64135c525433e87648bda30de) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2011/04/07 14:51:25.0015 3884 Kbdclass (1704d8c4c8807b889e43c649b478a452) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2011/04/07 14:51:25.0109 3884 kbdhid (b6d6c117d771c98130497265f26d1882) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
2011/04/07 14:51:25.0156 3884 KeyScrambler (2fcdff8a230ae5e992239594cf0286a0) C:\WINDOWS\system32\drivers\keyscrambler.sys
2011/04/07 14:51:25.0203 3884 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2011/04/07 14:51:25.0250 3884 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
2011/04/07 14:51:25.0328 3884 Lbd (419590ebe7855215bb157ea0cf0d0531) C:\WINDOWS\system32\DRIVERS\Lbd.sys
2011/04/07 14:51:25.0390 3884 lirsgt (975b6cf65f44e95883f3855bae8cecaf) C:\WINDOWS\system32\DRIVERS\lirsgt.sys
2011/04/07 14:51:25.0453 3884 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2011/04/07 14:51:25.0468 3884 Modem (6fb74ebd4ec57a6f1781de3852cc3362) C:\WINDOWS\system32\drivers\Modem.sys
2011/04/07 14:51:25.0593 3884 Monfilt (9fa7207d1b1adead88ae8eed9cdbbaa5) C:\WINDOWS\system32\drivers\Monfilt.sys
2011/04/07 14:51:25.0687 3884 Mouclass (b24ce8005deab254c0251e15cb71d802) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2011/04/07 14:51:25.0718 3884 mouhid (66a6f73c74e1791464160a7065ce711a) C:\WINDOWS\system32\DRIVERS\mouhid.sys
2011/04/07 14:51:25.0750 3884 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2011/04/07 14:51:25.0812 3884 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2011/04/07 14:51:25.0859 3884 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2011/04/07 14:51:25.0953 3884 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2011/04/07 14:51:26.0000 3884 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2011/04/07 14:51:26.0031 3884 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2011/04/07 14:51:26.0046 3884 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2011/04/07 14:51:26.0093 3884 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2011/04/07 14:51:26.0140 3884 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
2011/04/07 14:51:26.0234 3884 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
2011/04/07 14:51:26.0265 3884 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
2011/04/07 14:51:26.0296 3884 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2011/04/07 14:51:26.0328 3884 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
2011/04/07 14:51:26.0359 3884 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2011/04/07 14:51:26.0437 3884 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2011/04/07 14:51:26.0468 3884 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2011/04/07 14:51:26.0515 3884 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
2011/04/07 14:51:26.0546 3884 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2011/04/07 14:51:26.0578 3884 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2011/04/07 14:51:26.0671 3884 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2011/04/07 14:51:26.0734 3884 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2011/04/07 14:51:26.0828 3884 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2011/04/07 14:51:26.0875 3884 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2011/04/07 14:51:26.0906 3884 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2011/04/07 14:51:26.0953 3884 Parport (f84785660305b9b903fb3bca8ba29837) C:\WINDOWS\system32\drivers\Parport.sys
2011/04/07 14:51:27.0015 3884 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2011/04/07 14:51:27.0093 3884 ParVdm (c2bf987829099a3eaa2ca6a0a90ecb4f) C:\WINDOWS\system32\drivers\ParVdm.sys
2011/04/07 14:51:27.0109 3884 PCI (387e8dedc343aa2d1efbc30580273acd) C:\WINDOWS\system32\DRIVERS\pci.sys
2011/04/07 14:51:27.0156 3884 PCIIde (59ba86d9a61cbcf4df8e598c331f5b82) C:\WINDOWS\system32\DRIVERS\pciide.sys
2011/04/07 14:51:27.0187 3884 Pcmcia (a2a966b77d61847d61a3051df87c8c97) C:\WINDOWS\system32\drivers\Pcmcia.sys
2011/04/07 14:51:27.0218 3884 pcouffin (02aaafb7ba137ce5ddabcdf8090954d9) C:\WINDOWS\system32\Drivers\pcouffin.sys
2011/04/07 14:51:27.0437 3884 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2011/04/07 14:51:27.0484 3884 PQNTDrv (590f057b19488420f720bf6423388775) C:\WINDOWS\system32\drivers\PQNTDrv.sys
2011/04/07 14:51:27.0500 3884 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
2011/04/07 14:51:27.0515 3884 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2011/04/07 14:51:27.0562 3884 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\WINDOWS\system32\Drivers\PxHelp20.sys
2011/04/07 14:51:27.0593 3884 pxscan (a5b3922b9f821fc8ff2821423e40026c) C:\WINDOWS\system32\drivers\pxscan.sys
2011/04/07 14:51:27.0609 3884 pxsec (6613bbed3b306aee00d8a7b8d4cad5cd) C:\WINDOWS\system32\drivers\pxsec.sys
2011/04/07 14:51:27.0734 3884 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2011/04/07 14:51:27.0796 3884 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2011/04/07 14:51:27.0812 3884 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2011/04/07 14:51:27.0828 3884 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2011/04/07 14:51:27.0875 3884 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2011/04/07 14:51:27.0890 3884 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2011/04/07 14:51:27.0937 3884 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
2011/04/07 14:51:27.0984 3884 redbook (ed761d453856f795a7fe056e42c36365) C:\WINDOWS\system32\DRIVERS\redbook.sys
2011/04/07 14:51:28.0015 3884 RFCOMM (851c30df2807fcfa21e4c681a7d6440e) C:\WINDOWS\system32\DRIVERS\rfcomm.sys
2011/04/07 14:51:28.0125 3884 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2011/04/07 14:51:28.0156 3884 Serial (cf24eb4f0412c82bcd1f4f35a025e31d) C:\WINDOWS\system32\drivers\Serial.sys
2011/04/07 14:51:28.0187 3884 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
2011/04/07 14:51:28.0265 3884 SiS315 (4fabfab9231f7e7c833677377cf013b8) C:\WINDOWS\system32\DRIVERS\sisgrp.sys
2011/04/07 14:51:28.0343 3884 SiSGbeXP (ded793c377fa132912b4381043a4d554) C:\WINDOWS\system32\DRIVERS\SiSGbeXP.sys
2011/04/07 14:51:28.0375 3884 SiSkp (82387bf8f5a35358118b2129ff91c890) C:\WINDOWS\system32\DRIVERS\srvkp.sys
2011/04/07 14:51:28.0421 3884 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
2011/04/07 14:51:28.0468 3884 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
2011/04/07 14:51:28.0531 3884 sptd (71e276f6d189413266ea22171806597b) C:\WINDOWS\system32\Drivers\sptd.sys
2011/04/07 14:51:28.0531 3884 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: 71e276f6d189413266ea22171806597b
2011/04/07 14:51:28.0531 3884 sptd - detected Locked file (1)
2011/04/07 14:51:28.0625 3884 sr (50fa898f8c032796d3b1b9951bb5a90f) C:\WINDOWS\system32\DRIVERS\sr.sys
2011/04/07 14:51:28.0687 3884 Srv (0f6aefad3641a657e18081f52d0c15af) C:\WINDOWS\system32\DRIVERS\srv.sys
2011/04/07 14:51:28.0781 3884 ssmdrv (a36ee93698802cd899f98bfd553d8185) C:\WINDOWS\system32\DRIVERS\ssmdrv.sys
2011/04/07 14:51:28.0843 3884 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
2011/04/07 14:51:28.0890 3884 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
2011/04/07 14:51:28.0953 3884 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
2011/04/07 14:51:29.0109 3884 SynTP (d7b9ad3abd0f7f9f694d71f38b5c7b72) C:\WINDOWS\system32\DRIVERS\SynTP.sys
2011/04/07 14:51:29.0140 3884 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
2011/04/07 14:51:29.0203 3884 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2011/04/07 14:51:29.0281 3884 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
2011/04/07 14:51:29.0312 3884 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
2011/04/07 14:51:29.0343 3884 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
2011/04/07 14:51:29.0421 3884 TrmbTS (5070590587118b2960e14927b4393d32) C:\WINDOWS\system32\Drivers\TrmbTS.sys
2011/04/07 14:51:29.0453 3884 TRMUSB5K (53908ad09d37d86db3d7c00aced738e1) C:\WINDOWS\system32\drivers\TRMUSB5K.sys
2011/04/07 14:51:29.0562 3884 uagp35 (d85938f272d1bcf3db3a31fc0a048928) C:\WINDOWS\system32\DRIVERS\uagp35.sys
2011/04/07 14:51:29.0609 3884 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
2011/04/07 14:51:29.0671 3884 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
2011/04/07 14:51:29.0781 3884 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
2011/04/07 14:51:29.0812 3884 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2011/04/07 14:51:29.0843 3884 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2011/04/07 14:51:29.0890 3884 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys
2011/04/07 14:51:29.0984 3884 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
2011/04/07 14:51:30.0031 3884 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
2011/04/07 14:51:30.0109 3884 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2011/04/07 14:51:30.0187 3884 usb_rndisx (b6cc50279d6cd28e090a5d33244adc9a) C:\WINDOWS\system32\DRIVERS\usb8023x.sys
2011/04/07 14:51:30.0218 3884 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
2011/04/07 14:51:30.0296 3884 VolSnap (a5a712f4e880874a477af790b5186e1d) C:\WINDOWS\system32\drivers\VolSnap.sys
2011/04/07 14:51:30.0390 3884 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2011/04/07 14:51:30.0421 3884 wceusbsh (46a247f6617526afe38b6f12f5512120) C:\WINDOWS\system32\DRIVERS\wceusbsh.sys
2011/04/07 14:51:30.0468 3884 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
2011/04/07 14:51:30.0546 3884 wip0204 (2944bed10ffd9369da9a988d8ac899e4) C:\WINDOWS\system32\DRIVERS\wip0204.sys
2011/04/07 14:51:30.0640 3884 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
2011/04/07 14:51:30.0687 3884 zntport (bdfa6a3a7ce1d083889b316a484a356a) C:\WINDOWS\system32\drivers\zntport.sys
2011/04/07 14:51:30.0875 3884 ================================================================================
2011/04/07 14:51:30.0875 3884 Scan finished
2011/04/07 14:51:30.0875 3884 ================================================================================
2011/04/07 14:51:30.0906 5556 Detected object count: 1
2011/04/07 14:51:44.0859 5556 Locked file(sptd) - User select action: Skip

cosinus 07.04.2011 14:38

Weiter gehts: Mit GMER und OSAM Logs erstellen und posten.

GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.


Downloade Dir danach bitte MBRCheck (by a_d_13) und speichere die Datei auf dem Desktop.
  • Doppelklick auf die MBRCheck.exe.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Das Tool braucht nur wenige Sekunden.
  • Danach solltest du eine MBRCheck_<Datum>_<Uhrzeit>.txt auf dem Desktop finden.
Poste mir bitte den Inhalt des .txt Dokumentes

el_ukas 08.04.2011 18:20

Hier erstmal der gmer-Log:

GMER Logfile:
Code:

GMER 1.0.15.15570 - hxxp://www.gmer.net
Rootkit scan 2011-04-08 19:19:40
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e Hitachi_HTS543216L9A300 rev.FB2OC40C
Running: 2183h2oz.exe; Driver: C:\DOKUME~1\LUKEFI~1\LOKALE~1\Temp\pxtdapow.sys


---- System - GMER 1.0.15 ----

SSDT            BA6871A6                                                                                                            ZwCreateKey
SSDT            BA68719C                                                                                                            ZwCreateThread
SSDT            BA6871AB                                                                                                            ZwDeleteKey
SSDT            BA6871B5                                                                                                            ZwDeleteValueKey
SSDT            spqw.sys                                                                                                            ZwEnumerateKey [0xB9EC6CA2]
SSDT            spqw.sys                                                                                                            ZwEnumerateValueKey [0xB9EC7030]
SSDT            BA6871BA                                                                                                            ZwLoadKey
SSDT            spqw.sys                                                                                                            ZwOpenKey [0xB9EA80C0]
SSDT            BA687188                                                                                                            ZwOpenProcess
SSDT            BA68718D                                                                                                            ZwOpenThread
SSDT            spqw.sys                                                                                                            ZwQueryKey [0xB9EC7108]
SSDT            spqw.sys                                                                                                            ZwQueryValueKey [0xB9EC6F88]
SSDT            BA6871C4                                                                                                            ZwReplaceKey
SSDT            BA6871BF                                                                                                            ZwRestoreKey
SSDT            BA6871B0                                                                                                            ZwSetValueKey
SSDT            pxsec.sys (Prevx Realtime Analysis/Prevx)                                                                            ZwTerminateProcess [0xBA10A680]

INT 0x62        ?                                                                                                                    89D70BF8
INT 0x63        ?                                                                                                                    89B3BBF8
INT 0x73        ?                                                                                                                    89D70BF8
INT 0x94        ?                                                                                                                    89B3BBF8
INT 0xA4        ?                                                                                                                    89B3BBF8
INT 0xB1        ?                                                                                                                    89D72DD8

---- Kernel code sections - GMER 1.0.15 ----

?              spqw.sys                                                                                                            Das System kann die angegebene Datei nicht finden. !
.text          USBPORT.SYS!DllUnload                                                                                                B9ADA8AC 5 Bytes  JMP 89B3B1D8
.text          aoyi4qlo.SYS                                                                                                        B99DE386 35 Bytes  [00, 00, 00, 00, 00, 00, 20, ...]
.text          aoyi4qlo.SYS                                                                                                        B99DE3AA 24 Bytes  [00, 00, 00, 00, 00, 00, 00, ...]
.text          aoyi4qlo.SYS                                                                                                        B99DE3C4 3 Bytes  [00, 70, 02] {ADD [EAX+0x2], DH}
.text          aoyi4qlo.SYS                                                                                                        B99DE3C9 1 Byte  [2E]
.text          aoyi4qlo.SYS                                                                                                        B99DE3C9 11 Bytes  [2E, 00, 00, 00, 5C, 02, 00, ...] {ADD CS:[EAX], AL; ADD [EDX+EAX+0x0], BL; ADD [EAX], AL; ADD [EAX], AL}
.text          ...                                                                                                                 
.text          C:\WINDOWS\system32\DRIVERS\atksgt.sys                                                                              section is writeable [0xA2962300, 0x3ACC8, 0xE8000020]
.text          C:\WINDOWS\system32\DRIVERS\lirsgt.sys                                                                              section is writeable [0xBA450300, 0x1B7E, 0xE8000020]

---- User code sections - GMER 1.0.15 ----

.text          C:\Programme\Winamp\winamp.exe[3516] kernel32.dll!CreateProcessW                                                    7C802336 5 Bytes  JMP 100024D0 C:\WINDOWS\system32\AirfoilInject3.dll
.text          C:\Programme\Winamp\winamp.exe[3516] kernel32.dll!CreateProcessA                                                    7C80236B 5 Bytes  JMP 10002380 C:\WINDOWS\system32\AirfoilInject3.dll
.text          C:\Programme\Winamp\winamp.exe[3516] USER32.dll!CreateWindowExW                                                      7E37D0A3 5 Bytes  JMP 10005AC0 C:\WINDOWS\system32\AirfoilInject3.dll
.text          C:\Programme\Winamp\winamp.exe[3516] USER32.dll!CreateWindowExA                                                      7E37E4A9 5 Bytes  JMP 10005AA0 C:\WINDOWS\system32\AirfoilInject3.dll
.text          C:\Programme\Winamp\winamp.exe[3516] ADVAPI32.dll!CreateProcessAsUserW                                              77DBA8A9 5 Bytes  JMP 100026C0 C:\WINDOWS\system32\AirfoilInject3.dll
.text          C:\Programme\Winamp\winamp.exe[3516] ADVAPI32.dll!CreateProcessAsUserA                                              77DE0CE8 5 Bytes  JMP 10002630 C:\WINDOWS\system32\AirfoilInject3.dll

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT            atapi.sys[HAL.dll!READ_PORT_UCHAR]                                                                                  [B9EA9040] spqw.sys
IAT            atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT]                                                                          [B9EA913C] spqw.sys
IAT            atapi.sys[HAL.dll!READ_PORT_USHORT]                                                                                  [B9EA90BE] spqw.sys
IAT            atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT]                                                                          [B9EA97FC] spqw.sys
IAT            atapi.sys[HAL.dll!WRITE_PORT_UCHAR]                                                                                  [B9EA96D2] spqw.sys
IAT            \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR]                                                  [B9EB9048] spqw.sys
IAT            \SystemRoot\System32\Drivers\aoyi4qlo.SYS[HAL.dll!KfAcquireSpinLock]                                                4B8BDF8B
IAT            \SystemRoot\System32\Drivers\aoyi4qlo.SYS[HAL.dll!READ_PORT_UCHAR]                                                  8D3F0304
IAT            \SystemRoot\System32\Drivers\aoyi4qlo.SYS[HAL.dll!KeGetCurrentIrql]                                                  CB033043
IAT            \SystemRoot\System32\Drivers\aoyi4qlo.SYS[HAL.dll!KfRaiseIrql]                                                      0673C13B
IAT            \SystemRoot\System32\Drivers\aoyi4qlo.SYS[HAL.dll!KfLowerIrql]                                                      C13B0003
IAT            \SystemRoot\System32\Drivers\aoyi4qlo.SYS[HAL.dll!HalGetInterruptVector]                                            8366FA72
IAT            \SystemRoot\System32\Drivers\aoyi4qlo.SYS[HAL.dll!HalTranslateBusAddress]                                            75000E7B
IAT            \SystemRoot\System32\Drivers\aoyi4qlo.SYS[HAL.dll!KeStallExecutionProcessor]                                        0B7D80E3
IAT            \SystemRoot\System32\Drivers\aoyi4qlo.SYS[HAL.dll!KfReleaseSpinLock]                                                307B8D00
IAT            \SystemRoot\System32\Drivers\aoyi4qlo.SYS[HAL.dll!READ_PORT_BUFFER_USHORT]                                          00AA840F
IAT            \SystemRoot\System32\Drivers\aoyi4qlo.SYS[HAL.dll!READ_PORT_USHORT]                                                  83660000
IAT            \SystemRoot\System32\Drivers\aoyi4qlo.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT]                                          6A000E7A
IAT            \SystemRoot\System32\Drivers\aoyi4qlo.SYS[HAL.dll!WRITE_PORT_UCHAR]                                                  C6647400
IAT            \SystemRoot\System32\Drivers\aoyi4qlo.SYS[WMILIB.SYS!WmiSystemControl]                                              4F8B0200
IAT            \SystemRoot\System32\Drivers\aoyi4qlo.SYS[WMILIB.SYS!WmiCompleteRequest]                                            968D5140

---- Devices - GMER 1.0.15 ----

Device          \FileSystem\Ntfs \Ntfs                                                                                              89D6F1F8

AttachedDevice  \Driver\Kbdclass \Device\KeyboardClass0                                                                              Ch2kPS2.sys (Cherry PS2 driver for Win2k/Cherry GmbH)
AttachedDevice  \Driver\Kbdclass \Device\KeyboardClass1                                                                              Ch2kPS2.sys (Cherry PS2 driver for Win2k/Cherry GmbH)

Device          \Driver\usbohci \Device\USBPDO-0                                                                                    89B3A1F8
Device          \Driver\usbohci \Device\USBPDO-1                                                                                    89B3A1F8
Device          \Driver\usbehci \Device\USBPDO-2                                                                                    89B4A500

AttachedDevice  \Driver\Tcpip \Device\Tcp                                                                                            Lbd.sys (Boot Driver/Lavasoft AB)

Device          \Driver\Ftdisk \Device\HarddiskVolume1                                                                              89DE21F8
Device          \Driver\Ftdisk \Device\HarddiskVolume2                                                                              89DE21F8
Device          \Driver\Cdrom \Device\CdRom0                                                                                        89B491F8
Device          \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3                                                                          [B9E21B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device          \Driver\atapi \Device\Ide\IdePort0                                                                                  [B9E21B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device          \Driver\atapi \Device\Ide\IdePort1                                                                                  [B9E21B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device          \Driver\atapi \Device\Ide\IdePort2                                                                                  [B9E21B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device          \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e                                                                          [B9E21B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device          \Driver\Cdrom \Device\CdRom1                                                                                        89B491F8
Device          \Driver\NetBT \Device\NetBt_Wins_Export                                                                              89989500
Device          \Driver\NetBT \Device\NetbiosSmb                                                                                    89989500
Device          \Driver\PCI_PNP1794 \Device\0000004d                                                                                spqw.sys
Device          \Driver\NetBT \Device\NetBT_Tcpip_{213476E9-2727-4224-8EE0-B489FD84F287}                                            89989500
Device          \Driver\usbohci \Device\USBFDO-0                                                                                    89B3A1F8
Device          \Driver\usbohci \Device\USBFDO-1                                                                                    89B3A1F8
Device          \FileSystem\MRxSmb \Device\LanmanDatagramReceiver                                                                    89957500
Device          \Driver\usbehci \Device\USBFDO-2                                                                                    89B4A500
Device          \FileSystem\MRxSmb \Device\LanmanRedirector                                                                          89957500
Device          \Driver\sptd \Device\790288044                                                                                      spqw.sys
Device          \Driver\NetBT \Device\NetBT_Tcpip_{C2C4AA95-10DB-4A6E-9BE3-495A3955C2DC}                                            89989500
Device          \Driver\Ftdisk \Device\FtControl                                                                                    89DE21F8
Device          \Driver\NetBT \Device\NetBT_Tcpip_{8D3DEADB-4129-483C-AC23-4EA701894FC7}                                            89989500
Device          \Driver\aoyi4qlo \Device\Scsi\aoyi4qlo1Port3Path0Target0Lun0                                                        89AEE1F8
Device          \Driver\aoyi4qlo \Device\Scsi\aoyi4qlo1                                                                              89AEE1F8
Device          \FileSystem\Cdfs \Cdfs                                                                                              89994500

---- Registry - GMER 1.0.15 ----

Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000272805bf3                                         
Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000272805bf3@0010c690e4a4                            0xED 0x74 0x28 0x98 ...
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1                                                                  771343423
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2                                                                  285507792
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0                                                                  1
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4                                   
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0                                  C:\Programme\DAEMON Tools Lite\
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0                                  0
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh                              0xE5 0xC2 0x61 0xFC ...
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001                           
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0                        0x20 0x01 0x00 0x00 ...
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh                      0xC3 0xD5 0x1D 0xBA ...
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40                     
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh                0x2C 0x26 0xC3 0x2A ...
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41                     
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh                0xE8 0xCB 0xB2 0x7E ...
Reg            HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\000272805bf3 (not active ControlSet)                     
Reg            HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\000272805bf3@0010c690e4a4                                0xED 0x74 0x28 0x98 ...
Reg            HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)               
Reg            HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0                                      C:\Programme\DAEMON Tools Lite\
Reg            HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0                                      0
Reg            HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh                                  0xE5 0xC2 0x61 0xFC ...
Reg            HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)       
Reg            HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0                            0x20 0x01 0x00 0x00 ...
Reg            HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh                          0xC3 0xD5 0x1D 0xBA ...
Reg            HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet) 
Reg            HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh                    0x2C 0x26 0xC3 0x2A ...
Reg            HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet) 
Reg            HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh                    0xE8 0xCB 0xB2 0x7E ...
Reg            HKLM\SOFTWARE\Classes\CLSID\{14427C58-FFDA-DC11-C543-A85CDB4A49C1}\Verb@                                           
Reg            HKLM\SOFTWARE\Classes\CLSID\{14427C58-FFDA-DC11-C543-A85CDB4A49C1}\Verb\0                                           
Reg            HKLM\SOFTWARE\Classes\CLSID\{14427C58-FFDA-DC11-C543-A85CDB4A49C1}\Verb\0@                                          &Bearbeiten,0,2
Reg            HKLM\SOFTWARE\Classes\CLSID\{14427C58-FFDA-DC11-C543-A85CDB4A49C1}\Verb\1                                           
Reg            HKLM\SOFTWARE\Classes\CLSID\{14427C58-FFDA-DC11-C543-A85CDB4A49C1}\Verb\1@                                          ?&ffnen,0,2

---- EOF - GMER 1.0.15 ----

--- --- ---

el_ukas 08.04.2011 18:35

Hier das OSAM_Log:

OSAM Logfile:
Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 19:34:12 on 08.04.2011

OS: Windows XP Home Edition Service Pack 3 (Build 2600)
Default Browser: Microsoft Corporation Internet Explorer 8.00.6001.18702

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Boot Execute]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Session Manager )-----
"BootExecute" - ? - C:\WINDOWS\system32\lsdelete.exe  (File found, but it contains no detailed information)

[Common]
-----( %SystemRoot%\Tasks )-----
"AppleSoftwareUpdate.job" - "Apple Inc." - C:\Programme\Apple Software Update\SoftwareUpdate.exe
"Ad-Aware Update (Weekly).job" - "Lavasoft" - C:\Programme\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe
"GoogleUpdateTaskUserS-1-5-21-746137067-1645522239-1177238915-1005Core.job" - "Google Inc." - C:\Dokumente und Einstellungen\Luke Firewalker\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskUserS-1-5-21-746137067-1645522239-1177238915-1005UA.job" - "Google Inc." - C:\Dokumente und Einstellungen\Luke Firewalker\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe
"1-Klick-Wartung.job" - "TuneUp Software GmbH" - C:\Programme\TuneUp Utilities 2009\OneClickStarter.exe

[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"bdeadmin.cpl" - ? - C:\WINDOWS\system32\bdeadmin.cpl
"infocardcpl.cpl" - "Microsoft Corporation" - C:\WINDOWS\system32\infocardcpl.cpl
"ISUSPM.cpl" - "Macrovision Corporation" - C:\WINDOWS\system32\ISUSPM.cpl
"javacpl.cpl" - "Sun Microsystems, Inc." - C:\WINDOWS\system32\javacpl.cpl
"PhysX.cpl" - "NVIDIA Corporation" - C:\WINDOWS\system32\PhysX.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"AirPort Disk Prefs" - "Apple Inc." - C:\Programme\AirPort\APDiskPrefs.exe
"Avira AntiVir Personal" - "Avira GmbH" - C:\PROGRA~1\Avira\ANTIVI~1\avconfig.cpl
"Nero BurnRights" - "Nero AG" - C:\Programme\Nero\Nero8\Nero Toolkit\NeroBurnRights.cpl
"QuickTime" - "Apple Inc." - C:\Programme\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"%USB\VID_04C8&PID_0720.DeviceDesc%" (Camavb) - "Samsung Inc." - C:\WINDOWS\System32\Drivers\Camavb.sys
"aoyi4qlo" (aoyi4qlo) - "Microsoft Corporation" - C:\WINDOWS\system32\drivers\aoyi4qlo.sys  (Hidden registry entry, rootkit activity | File signed by Microsoft)
"atksgt" (atksgt) - ? - C:\WINDOWS\System32\DRIVERS\atksgt.sys  (File found, but it contains no detailed information)
"avgio" (avgio) - "Avira GmbH" - C:\Programme\Avira\AntiVir Desktop\avgio.sys
"avgntflt" (avgntflt) - "Avira GmbH" - C:\WINDOWS\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\WINDOWS\System32\DRIVERS\avipbb.sys
"catchme" (catchme) - ? - C:\DOKUME~1\LUKEFI~1\LOKALE~1\Temp\catchme.sys  (File not found)
"Changer" (Changer) - ? - C:\WINDOWS\system32\drivers\Changer.sys  (File not found)
"Hamachi Network Interface" (hamachi) - "LogMeIn, Inc." - C:\WINDOWS\System32\DRIVERS\hamachi.sys
"i2omgmt" (i2omgmt) - ? - C:\WINDOWS\system32\drivers\i2omgmt.sys  (File not found)
"KeyScrambler" (KeyScrambler) - "QFX Software Corporation" - C:\WINDOWS\System32\drivers\keyscrambler.sys
"Lbd" (Lbd) - "Lavasoft AB" - C:\WINDOWS\System32\DRIVERS\Lbd.sys
"lbrtfdc" (lbrtfdc) - ? - C:\WINDOWS\system32\drivers\lbrtfdc.sys  (File not found)
"lirsgt" (lirsgt) - ? - C:\WINDOWS\System32\DRIVERS\lirsgt.sys  (File found, but it contains no detailed information)
"NTPort Library Driver" (zntport) - "Zeal SoftStudio" - C:\WINDOWS\system32\drivers\zntport.sys
"PCIDump" (PCIDump) - ? - C:\WINDOWS\system32\drivers\PCIDump.sys  (File not found)
"PDCOMP" (PDCOMP) - ? - C:\WINDOWS\system32\drivers\PDCOMP.sys  (File not found)
"PDFRAME" (PDFRAME) - ? - C:\WINDOWS\system32\drivers\PDFRAME.sys  (File not found)
"PDRELI" (PDRELI) - ? - C:\WINDOWS\system32\drivers\PDRELI.sys  (File not found)
"PDRFRAME" (PDRFRAME) - ? - C:\WINDOWS\system32\drivers\PDRFRAME.sys  (File not found)
"PQNTDrv" (PQNTDrv) - "PowerQuest Corporation" - C:\WINDOWS\system32\drivers\PQNTDrv.sys
"PxHelp20" (PxHelp20) - "Sonic Solutions" - C:\WINDOWS\System32\Drivers\PxHelp20.sys
"pxscan" (pxscan) - "Prevx" - C:\WINDOWS\System32\drivers\pxscan.sys
"pxsec" (pxsec) - "Prevx" - C:\WINDOWS\System32\drivers\pxsec.sys
"pxtdapow" (pxtdapow) - ? - C:\DOKUME~1\LUKEFI~1\LOKALE~1\Temp\pxtdapow.sys  (Hidden registry entry, rootkit activity | File not found)
"sptd" (sptd) - "Duplex Secure Ltd." - C:\WINDOWS\System32\Drivers\sptd.sys  (File is exclusively opened, access blocked)
"ssmdrv" (ssmdrv) - "Avira GmbH" - C:\WINDOWS\System32\DRIVERS\ssmdrv.sys
"Trimble USB GPS Driver" (TRMUSB5K) - "e-TEK Labs" - C:\WINDOWS\System32\drivers\TRMUSB5K.sys
"TrmbTS" (TrmbTS) - "Trimble AB, Sweden" - C:\WINDOWS\System32\Drivers\TrmbTS.sys
"VSO Software pcouffin" (pcouffin) - "VSO Software" - C:\WINDOWS\System32\Drivers\pcouffin.sys
"WDICA" (WDICA) - ? - C:\WINDOWS\system32\drivers\WDICA.sys  (File not found)
"Wippien Network Adapter 2.4" (wip0204) - "Wippien Software" - C:\WINDOWS\System32\DRIVERS\wip0204.sys

[Explorer]
-----( HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components )-----
{89B4C1CD-B018-4511-B0A1-5476DBF70820} "StubPath" - "Microsoft Corporation" - C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install
-----( HKLM\Software\Classes\Protocols\Filter )-----
{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
{807553E5-5146-11D5-A672-00B0D022E945} "text/xml" - "Microsoft Corporation" - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{32505114-5902-49B2-880A-1F7738E5A384} "Data Page Plugable Protocal mso-offdap11 Handler" - "Microsoft Corporation" - C:\PROGRA~1\GEMEIN~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
{3D9F03FA-7A94-11D3-BE81-0050048385D1} "Data Page Pluggable Protocol mso-offdap Handler" - "Microsoft Corporation" - C:\PROGRA~1\GEMEIN~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL
{5513F07E-936B-4E52-9B00-067394E91CC5} "McAfee SACore Protocol Handler" - "McAfee, Inc." - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
{5513F07E-936B-4E52-9B00-067394E91CC5} "McAfee SACore Protocol Handler" - "McAfee, Inc." - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension" - "Igor Pavlov" - C:\Programme\7-Zip\7-zip.dll
{D3F9A525-8824-497A-BE36-B23E22F141FC} "ACShell Class" - "Romain Petges" - C:\Programme\Attribute Changer\acshell.dll
{42071714-76d4-11d1-8b24-00a0c9068ff3} "CPL-Erweiterung für Anzeigeverschiebung" - ? - deskpan.dll  (File not found)
{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} "Kontextmenü für die Verschlüsselung" - ? -  (File not found | COM-object registry key not found)
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Programme\Microsoft Office\OFFICE11\msohev.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\GEMEIN~1\MICROS~1\OFFICE12\msoshext.dll
{00020D75-0000-0000-C000-000000000046} "Microsoft Office Outlook" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\GEMEIN~1\MICROS~1\OFFICE12\msoshext.dll
{97F68CE3-7146-45FF-BE24-D9A7DD7CB8A2} "NeroCoverEdLiveIcons Class" - "Nero AG" - C:\Programme\Nero\Nero8\Nero CoverDesigner\CoverEdExtension.dll
{0006F045-0000-0000-C000-000000000046} "Outlook-Dateisymbolerweiterung" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL
{CF822AB4-6DB5-4FDA-BC28-E61DF36D2583} "PDF-XChange PDF Preview Provider" - ? -  (File not found | COM-object registry key not found)
{5B043439-4F53-436E-8CFE-28F80934DBE6} "PDF-XChange PDF Preview Provider (XP)" - ? -  (File not found | COM-object registry key not found)
{67EB453C-1BE1-48EC-AAF3-23B10277FCC1} "PDF-XChange PDF Property Handler" - ? -  (File not found | COM-object registry key not found)
{EBD0B8F4-A9A0-41B7-9695-030CD264D9C8} "PDF-XChange PDF Thumbnail Provider" - ? -  (File not found | COM-object registry key not found)
{967B2D40-8B7D-4127-9049-61EA0C2C6DCE} "PowerISO" - ? -  (File not found | COM-object registry key not found)
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira GmbH" - C:\Programme\Avira\AntiVir Desktop\shlext.dll
{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} "Shell Icon Handler for Application References" - "Microsoft Corporation" - C:\WINDOWS\system32\dfshim.dll
{764BF0E1-F219-11ce-972D-00AA00A14F56} "Shellerweiterungen für die Dateikomprimierung" - ? -  (File not found | COM-object registry key not found)
{e82a2d71-5b2f-43a0-97b8-81be15854de8} "ShellLink for Application References" - "Microsoft Corporation" - C:\WINDOWS\system32\dfshim.dll
{D6B4E769-5C4B-4C27-B3D1-050CF8209712} "Trimble T00 File Context Menu" - ? - C:\PROGRA~1\GEMEIN~1\Trimble\ShellEx\T00ShExU.dll
{4838CD50-7E5D-4811-9B17-C47A85539F28} "TuneUp Disk Space Explorer Shell Extension" - "TuneUp Software" - C:\Programme\TuneUp Utilities 2009\DseShExt-x86.dll
{4858E7D9-8E12-45a3-B6A3-1CD128C9D403} "TuneUp Shredder Shell Extension" - "TuneUp Software" - C:\Programme\TuneUp Utilities 2009\SDShelEx-win32.dll
{44440D00-FF19-4AFC-B765-9A0970567D97} "TuneUp Theme Extension" - "TuneUp Software" - C:\WINDOWS\System32\uxtuneup.dll
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} "Webordner" - "Microsoft Corporation" - C:\PROGRA~1\GEMEIN~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
XCShInfo "{B2F55D43-C7A4-4B7C-90D7-7A860DFA9F2A}" - ? -  (File not found | COM-object registry key not found)

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
<binary data> "Gutscheinmieze" - ? - Gutscheinmieze\toolbar.dll  (File not found)
ITBar7Height "ITBar7Height" - ? -  (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -  (File not found | COM-object registry key not found)
<binary data> "ITBarLayout" - ? -  (File not found | COM-object registry key not found)
<binary data> "{C55BBCD6-41AD-48AD-9953-3609C48EACC7}" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_13" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\npjpi160_13.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} "Java Plug-in 1.6.0_13" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\npjpi160_13.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_13" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\npjpi160_13.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
{E2883E8F-472F-4FB0-9522-AC9BF37916A7} "{E2883E8F-472F-4FB0-9522-AC9BF37916A7}" - ? -  (File not found | COM-object registry key not found) / hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{E601996F-E400-41CA-804B-CD6373A7EEE2} "ClsidExtension" - ? -  (File not found | COM-object registry key not found)
{B745F984-EF2E-40D6-A9AC-D8CED7230E61} "ClsidExtension" - "QFX Software Corporation" - C:\Programme\KeyScrambler\KeyScramblerIE.dll
{FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Recherchieren" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
{DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} "Gutscheinmieze" - ? - Gutscheinmieze\toolbar.dll  (File not found)
{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} "McAfee SiteAdvisor Toolbar" - "McAfee, Inc." - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
<binary data> "pcwPrivilegien" - ? - C:\PROGRA~1\PC-WELT\PCWRUN~1\PCWPRI~1.DLL  (File found, but it contains no detailed information)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{2B9F5787-88A5-4945-90E7-C4B18563BC5E} "CKeyScramblerBHO Object" - "QFX Software Corporation" - C:\Programme\KeyScrambler\KeyScramblerIE.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\jp2ssv.dll
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} "JQSIEStartDetectorImpl Class" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
{B164E929-A1B6-4A06-B104-2CD0E90A88FF} "McAfee SiteAdvisor BHO" - "McAfee, Inc." - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
{C5D07EB6-BBCE-4DAE-ACBB-D13A8D28CB1F} "PDF-XChange Viewer IE-Plugin" - "Tracker Software Products Ltd." - C:\Programme\Tracker Software\PDF-XChange Viewer\pdf-viewer\PDFXCviewIEPlugin.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live Anmelde-Hilfsprogramm" - "Microsoft Corporation" - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

[Logon]
-----( %AllUsersProfile%\Startmenü\Programme\Autostart )-----
"desktop.ini" - ? - C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\desktop.ini
"Utility Tray.lnk" - "Silicon Integrated Systems Corporation" - C:\WINDOWS\system32\sistray.exe  (Shortcut exists | File exists)
"WirelessSelector.lnk" - "ITE Tech Inc." - C:\Programme\FSC\Wireless Utility\WirelessSelector.exe  (Shortcut exists | File exists)
-----( %UserProfile%\Startmenü\Programme\Autostart )-----
"desktop.ini" - ? - C:\Dokumente und Einstellungen\User\Startmenü\Programme\Autostart\desktop.ini
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"AirPort Base Station Agent" - "Apple Inc." - "C:\Programme\AirPort\APAgent.exe"
"avgnt" - "Avira GmbH" - "C:\Programme\Avira\AntiVir Desktop\avgnt.exe" /min
"QuickTime Task" - "Apple Inc." - "C:\Programme\QuickTime\QTTask.exe" -atboottime
"SiSPower" - "Silicon Integrated Systems Corporation" - Rundll32.exe SiSPower.dll,ModeAgent
"TouchPadHotKey" - ? - C:\Programme\FSC\TouchPad HotKey Utility\TouchPad_HotKey.exe

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"Microsoft Document Imaging Writer Monitor" - "Microsoft Corporation" - C:\WINDOWS\system32\mdimon.dll
"PDFCreator" - ? - C:\WINDOWS\system32\pdfcmnnt.dll  (File found, but it contains no detailed information)

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
".NET Runtime Optimization Service v2.0.50727_X86" (clr_optimization_v2.0.50727_32) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
"Anwendungsverwaltung" (AppMgmt) - ? - C:\WINDOWS\System32\appmgmts.dll  (File not found)
"ASP.NET-Zustandsdienst" (aspnet_state) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
"Avira AntiVir Guard" (AntiVirService) - "Avira GmbH" - C:\Programme\Avira\AntiVir Desktop\avguard.exe
"Avira AntiVir Planer" (AntiVirSchedulerService) - "Avira GmbH" - C:\Programme\Avira\AntiVir Desktop\sched.exe
"Cherry Device Interface" (Cherry Device Interface) - "Cherry, Auerbach Germany, www.cherry.de" - C:\Programme\Cherry\CDI\cdi.exe
"CSIScanner" (CSIScanner) - "Prevx" - C:\Programme\Prevx\prevx.exe
"Dienst "Bonjour"" (Bonjour Service) - "Apple Inc." - C:\Programme\Bonjour\mDNSResponder.exe
"FLEXnet Licensing Service" (FLEXnet Licensing Service) - "Macrovision Europe Ltd." - C:\Programme\Gemeinsame Dateien\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
"Java Quick Starter" (JavaQuickStarterService) - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\jqs.exe
"Lavasoft Ad-Aware Service" (Lavasoft Ad-Aware Service) - "Lavasoft" - C:\Programme\Lavasoft\Ad-Aware\AAWService.exe
"LogMeIn Hamachi 2.0 Tunneling Engine" (Hamachi2Svc) - "LogMeIn Inc." - C:\Programme\LogMeIn Hamachi\hamachi-2.exe
"McAfee SiteAdvisor Service" (McAfee SiteAdvisor Service) - "McAfee, Inc." - C:\Programme\McAfee\SiteAdvisor\McSACore.exe
"Nero BackItUp Scheduler 3" (Nero BackItUp Scheduler 3) - "Nero AG" - C:\Programme\Nero\Nero8\Nero BackItUp\NBService.exe
"NMIndexingService" (NMIndexingService) - "Nero AG" - C:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexingService.exe
"NMSAccessU" (NMSAccessU) - ? - C:\Programme\CDBurnerXP\NMSAccessU.exe  (File found, but it contains no detailed information)
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE
"TuneUp Designerweiterung" (UxTuneUp) - "TuneUp Software" - C:\WINDOWS\System32\uxtuneup.dll
"TuneUp Drive Defrag-Dienst" (TuneUp.Defrag) - "TuneUp Software" - C:\WINDOWS\System32\TuneUpDefragService.exe
"TuneUp Program Statistics Service" (TuneUp.ProgramStatisticsSvc) - "TuneUp Software" - C:\WINDOWS\System32\TUProgSt.exe
"Windows CardSpace" (idsvc) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
"Windows Presentation Foundation Font Cache 3.0.0.0" (FontCache3.0.0.0) - "Microsoft Corporation" - c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe

[Winlogon]
-----( HKCU\Control Panel\IOProcs )-----
"MVB" - ? - mvfs32.dll  (File not found)
-----( HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions )-----
{c6dc5466-785a-11d2-84d0-00c04fb169f7} "Softwareinstallation" - ? - appmgmts.dll  (File not found)

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"mdnsNSP" - "Apple Inc." - C:\Programme\Bonjour\mdnsNSP.dll

===[ Logfile end ]=========================================[ Logfile end ]===

--- --- ---

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru

gruß

el_ukas 08.04.2011 18:37

und noch die MBR_log:


MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows XP Home Edition
Windows Information: Service Pack 3 (build 2600)
Logical Drives Mask: 0x0000081c

Kernel Drivers (total 124):
0x804D7000 \WINDOWS\system32\ntkrnlpa.exe
0x806E6000 \WINDOWS\system32\hal.dll
0xBA5A8000 \WINDOWS\system32\KDCOM.DLL
0xBA4B8000 \WINDOWS\system32\BOOTVID.dll
0xB9EA7000 spqw.sys
0xBA5AA000 \WINDOWS\System32\Drivers\WMILIB.SYS
0xB9E8F000 \WINDOWS\System32\Drivers\SCSIPORT.SYS
0xB9E60000 ACPI.sys
0xB9E4F000 pci.sys
0xBA0A8000 isapnp.sys
0xBA4BC000 compbatt.sys
0xBA4C0000 \WINDOWS\system32\DRIVERS\BATTC.SYS
0xBA670000 pciide.sys
0xBA328000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
0xBA0B8000 MountMgr.sys
0xB9E30000 ftdisk.sys
0xBA4C4000 ACPIEC.sys
0xBA671000 \WINDOWS\system32\DRIVERS\OPRGHDLR.SYS
0xBA330000 PartMgr.sys
0xBA0C8000 pxscan.sys
0xBA0D8000 VolSnap.sys
0xB9E18000 atapi.sys
0xBA0E8000 disk.sys
0xBA0F8000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
0xB9DF8000 fltMgr.sys
0xB9DE6000 sr.sys
0xBA108000 pxsec.sys
0xBA118000 Lbd.sys
0xBA128000 PxHelp20.sys
0xB9DCF000 KSecDD.sys
0xB9D42000 Ntfs.sys
0xB9D15000 NDIS.sys
0xBA138000 uagp35.sys
0xB9CFB000 Mup.sys
0xBA158000 \SystemRoot\system32\DRIVERS\intelppm.sys
0xB9CCB000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0xB9B8D000 \SystemRoot\system32\DRIVERS\sisgrp.sys
0xB9B79000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xBA168000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0xB9B43000 \SystemRoot\system32\DRIVERS\SynTP.sys
0xBA5D8000 \SystemRoot\system32\DRIVERS\USBD.SYS
0xBA430000 \SystemRoot\system32\DRIVERS\mouclass.sys
0xB9B23000 \SystemRoot\system32\DRIVERS\Ch2kPS2.sys
0xB9B09000 \SystemRoot\System32\drivers\keyscrambler.sys
0xBA438000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0xBA178000 \SystemRoot\system32\DRIVERS\imapi.sys
0xBA188000 \SystemRoot\system32\DRIVERS\cdrom.sys
0xBA198000 \SystemRoot\system32\DRIVERS\redbook.sys
0xB9AE6000 \SystemRoot\system32\DRIVERS\ks.sys
0xBA440000 \SystemRoot\system32\DRIVERS\usbohci.sys
0xB9AC2000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0xBA448000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xBA1A8000 \SystemRoot\system32\DRIVERS\SiSGbeXP.sys
0xB9A3C000 \SystemRoot\system32\DRIVERS\ar5211.sys
0xB9A14000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0xB99DE000 \SystemRoot\System32\Drivers\aoyi4qlo.SYS
0xBA70E000 \SystemRoot\system32\DRIVERS\audstub.sys
0xBA1B8000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0xB9C01000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0xB99C7000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0xBA1C8000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0xBA1D8000 \SystemRoot\system32\DRIVERS\raspptp.sys
0xBA4A8000 \SystemRoot\system32\DRIVERS\TDI.SYS
0xB99B6000 \SystemRoot\system32\DRIVERS\psched.sys
0xBA1E8000 \SystemRoot\system32\DRIVERS\msgpc.sys
0xBA4B0000 \SystemRoot\system32\DRIVERS\ptilink.sys
0xBA340000 \SystemRoot\system32\DRIVERS\raspti.sys
0xBA348000 \SystemRoot\system32\DRIVERS\hamachi.sys
0xBA1F8000 \SystemRoot\system32\DRIVERS\termdd.sys
0xBA5DE000 \SystemRoot\system32\DRIVERS\swenum.sys
0xB98B8000 \SystemRoot\system32\DRIVERS\update.sys
0xB9BED000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0xBA208000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xBA248000 \SystemRoot\system32\DRIVERS\usbhub.sys
0xA336E000 \SystemRoot\system32\drivers\RtkHDAud.sys
0xA334A000 \SystemRoot\system32\drivers\portcls.sys
0xBA268000 \SystemRoot\system32\drivers\drmk.sys
0xBA620000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xBA7F4000 \SystemRoot\System32\Drivers\Null.SYS
0xBA622000 \SystemRoot\System32\Drivers\Beep.SYS
0xBA3A8000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0xBA3B0000 \SystemRoot\System32\drivers\vga.sys
0xBA624000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xBA626000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xBA3B8000 \SystemRoot\System32\Drivers\Msfs.SYS
0xBA3C0000 \SystemRoot\System32\Drivers\Npfs.SYS
0xB9CC3000 \SystemRoot\system32\DRIVERS\rasacd.sys
0xA32EF000 \SystemRoot\system32\DRIVERS\ipsec.sys
0xA3296000 \SystemRoot\system32\DRIVERS\tcpip.sys
0xA326E000 \SystemRoot\system32\DRIVERS\netbt.sys
0xA3248000 \SystemRoot\system32\DRIVERS\ipnat.sys
0xA3226000 \SystemRoot\System32\drivers\afd.sys
0xBA2A8000 \SystemRoot\system32\DRIVERS\netbios.sys
0xBA3C8000 \SystemRoot\system32\DRIVERS\ssmdrv.sys
0xBA3D0000 \SystemRoot\system32\DRIVERS\srvkp.sys
0xA31FB000 \SystemRoot\system32\DRIVERS\rdbss.sys
0xBA685000 \SystemRoot\System32\Drivers\PQNTDrv.SYS
0xA3163000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xBA2B8000 \SystemRoot\System32\Drivers\Fips.SYS
0xA309D000 \SystemRoot\system32\DRIVERS\avipbb.sys
0xBA62A000 \??\C:\Programme\Avira\AntiVir Desktop\avgio.sys
0xBA2E8000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xA3085000 \SystemRoot\System32\Drivers\dump_atapi.sys
0xBA644000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
0xBF800000 \SystemRoot\System32\win32k.sys
0xA3346000 \SystemRoot\System32\drivers\Dxapi.sys
0xBA3E8000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xBA775000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF012000 \SystemRoot\System32\SiSGRV.dll
0xBF45D000 \SystemRoot\System32\ATMFD.DLL
0xA2F30000 \SystemRoot\system32\DRIVERS\avgntflt.sys
0xBA2F8000 \SystemRoot\system32\DRIVERS\wanarp.sys
0xA2F2C000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0xA2BD3000 \SystemRoot\system32\drivers\wdmaud.sys
0xA2D30000 \SystemRoot\system32\drivers\sysaudio.sys
0xA2962000 \SystemRoot\system32\DRIVERS\atksgt.sys
0xBA450000 \SystemRoot\system32\DRIVERS\lirsgt.sys
0xA281A000 \SystemRoot\system32\DRIVERS\srv.sys
0xBA68D000 \??\C:\WINDOWS\system32\drivers\zntport.sys
0xA2159000 \SystemRoot\System32\Drivers\HTTP.sys
0xA1B86000 \??\C:\DOKUME~1\LUKEFI~1\LOKALE~1\Temp\pxtdapow.sys
0x7C910000 \WINDOWS\system32\ntdll.dll
0x10000000 \Programme\DAEMON Tools Lite\daemon.dll

Processes (total 48):
0 System Idle Process
4 System
488 C:\WINDOWS\system32\smss.exe
572 csrss.exe
620 C:\WINDOWS\system32\winlogon.exe
664 C:\WINDOWS\system32\services.exe
676 C:\WINDOWS\system32\lsass.exe
876 C:\WINDOWS\system32\svchost.exe
1268 svchost.exe
1412 C:\WINDOWS\system32\svchost.exe
1520 svchost.exe
1696 svchost.exe
1964 C:\Programme\Lavasoft\Ad-Aware\AAWService.exe
184 C:\WINDOWS\system32\spoolsv.exe
260 C:\WINDOWS\explorer.exe
348 C:\Programme\Avira\AntiVir Desktop\sched.exe
1056 C:\Programme\Synaptics\SynTP\SynTPEnh.exe
1060 C:\Programme\FSC\TouchPad HotKey Utility\TouchPad_HotKey.exe
1068 C:\WINDOWS\RTHDCPL.EXE
1084 C:\Programme\Avira\AntiVir Desktop\avgnt.exe
1108 C:\Programme\AirPort\APAgent.exe
1132 C:\Programme\Gemeinsame Dateien\Nero\Lib\NMBgMonitor.exe
1224 C:\WINDOWS\system32\sistray.exe
1308 C:\Programme\FSC\Wireless Utility\WirelessSelector.exe
1564 C:\Programme\Avira\AntiVir Desktop\avguard.exe
920 C:\Programme\Bonjour\mDNSResponder.exe
1612 svchost.exe
1624 C:\Programme\Prevx\prevx.exe
1840 C:\Programme\LogMeIn Hamachi\hamachi-2.exe
1024 C:\Programme\Java\jre6\bin\jqs.exe
1160 C:\Programme\McAfee\SiteAdvisor\McSACore.exe
1196 C:\Programme\Avira\AntiVir Desktop\avshadow.exe
1332 C:\Programme\Nero\Nero8\Nero BackItUp\NBService.exe
1476 C:\Programme\CDBurnerXP\NMSAccessU.exe
1880 C:\WINDOWS\system32\svchost.exe
2024 C:\WINDOWS\system32\TUProgSt.exe
4032 C:\Programme\Prevx\prevx.exe
2296 C:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexingService.exe
3636 unsecapp.exe
3644 wmiprvse.exe
3732 C:\WINDOWS\system32\rundll32.exe
3888 C:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexStoreSvr.exe
2084 C:\WINDOWS\system32\wbem\wmiapsrv.exe
736 alg.exe
3016 C:\Programme\Lavasoft\Ad-Aware\AAWTray.exe
2404 C:\WINDOWS\system32\svchost.exe
1824 C:\Programme\Mozilla Firefox\firefox.exe
3504 L:\Downloads\Sicherheit\MBRCheck.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
\\.\L: --> \\.\PhysicalDrive0 at offset 0x0000000c`d8b2e600 (NTFS)

PhysicalDrive0 Model Number: HitachiHTS543216L9A300, Rev: FB2OC40C

Size Device Name MBR Status
--------------------------------------------
149 GB \\.\PhysicalDrive0 Windows XP MBR code detected
SHA1: ADFE55CD0C6ED2E00B22375835E4C2736CE9AD11


Done!

Gruß

el_ukas

cosinus 08.04.2011 18:52

Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

el_ukas 09.04.2011 15:18

SuperAntiSpyware_Log:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 04/09/2011 at 04:07 PM

Application Version : 4.50.1002

Core Rules Database Version : 6795
Trace Rules Database Version: 4607

Scan type : Complete Scan
Total Scan Time : 02:24:46

Memory items scanned : 641
Memory threats detected : 0
Registry items scanned : 8009
Registry threats detected : 0
File items scanned : 142733
File threats detected : 1

Trojan.Agent/CDesc[Generic]
C:\SYSTEM VOLUME INFORMATION\_RESTORE{D72491C4-64F3-4BDD-B3D8-0B3D1BCE5B6A}\RP1\A0000091.DLL



Malwarebytes-AntiMalware_Log:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6318

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

09.04.2011 13:35:07
mbam-log-2011-04-09 (13-35-07).txt

Scan type: Full scan (C:\|L:\|)
Objects scanned: 306289
Time elapsed: 1 hour(s), 42 minute(s), 25 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)



Gruß

el_ukas

cosinus 09.04.2011 15:25

Nur ein Überrest.
Rechner wieder ok?

el_ukas 09.04.2011 16:04

Cool...Danke vielmals.

Ein neu aufspielen ist in jedem Fall überflüssig??

Gruß

el_ukas

cosinus 09.04.2011 16:19

Dann wären wir durch! :abklatsch:

Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update



PDF-Reader aktualisieren
Dein Adobe Reader ist nicht aktuell, was ein großes Sicherheitsrisiko darstellt. Du solltest daher besser die alte Version über Systemsteuerung => Software deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst.

Ich empfehle einen alternativen PDF-Reader wie SumatraPDF oder Foxit PDF Reader, beide sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers, hier der direkte Downloadlink:

Mozilla und andere Browser => http://filepony.de/?q=Flash+Player
Internet Explorer => http://fpdownload.adobe.com/get/flas..._player_ax.exe


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.


Alle Zeitangaben in WEZ +1. Es ist jetzt 02:48 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131