Hi Ralf,
danke für die tolle Hilfe! Ja der Server wird für alles mögliche verwendet... hauptsächlich für Video, Internet, Fotos etc. eben auch für Downloads/Uploads... da muss es passiert sein.
Die Files hab ich gemailt. Allerdings bekomme ich Fehlermeldung vom Mailserver retour:
<virus@rokop-xecurity.de>:
Sorry, I couldn't find any host named rokop-xecurity.de.
Die Keys mit Hijacthis gelöscht.... sind bei neuem Scan dann weg gewesen.
Hier das Combofix Log:
"Administrator" - 07-04-18 20:39:40 Service Pack 1
ComboFix 07-04-18.2V - Running from:
((((((((((((((((((((((((((((((( Files Created from 2007-03-18 to 2007-04-18 ))))))))))))))))))))))))))))))))))
2007-04-18 20:43 <DIR> d-------- E:\QooBox
2007-04-18 20:43 <DIR> d-------- E:\QooBox
2007-04-18 20:43 <DIR> d-------- E:\QooBox
2007-04-18 20:43 <DIR> d-------- E:\QooBox
2007-04-18 20:43 <DIR> d-------- E:\QooBox
2007-04-18 20:43 <DIR> d-------- E:\QooBox
2007-04-18 20:43 <DIR> d-------- E:\QooBox
2007-04-18 20:43 <DIR> d-------- E:\QooBox
2007-04-18 20:43 <DIR> d-------- E:\QooBox
2007-04-18 20:43 <DIR> d-------- E:\QooBox
2007-04-18 20:43 <DIR> d-------- E:\QooBox
2007-04-18 20:43 <DIR> d-------- E:\QooBox
2007-04-18 20:43 <DIR> d-------- E:\QooBox
2007-04-18 20:43 <DIR> d-------- E:\QooBox
2007-04-18 20:43 <DIR> d-------- E:\QooBox
2007-04-18 20:43 <DIR> d-------- E:\QooBox
2007-04-18 20:43 <DIR> d-------- E:\QooBox
2007-04-18 20:39 642 --------- E:\Download\Symantec\ComboFix\ComboFixT\history.bat
2007-04-18 20:39 642 --------- E:\Download\Symantec\ComboFix\ComboFixT\history.bat
2007-04-18 20:39 642 --------- E:\Download\Symantec\ComboFix\ComboFixT\history.bat
2007-04-18 20:39 5,824 --a------ E:\Download\Symantec\ComboFix\ComboFixT\Sys.bat
2007-04-18 20:39 5,824 --a------ E:\Download\Symantec\ComboFix\ComboFixT\Sys.bat
2007-04-18 20:39 5,824 --a------ E:\Download\Symantec\ComboFix\ComboFixT\Sys.bat
2007-04-18 20:39 5,052 --------- E:\Download\Symantec\ComboFix\ComboFixT\NTPBack.exe
2007-04-18 20:39 5,052 --------- E:\Download\Symantec\ComboFix\ComboFixT\NTPBack.exe
2007-04-18 20:39 5,052 --------- E:\Download\Symantec\ComboFix\ComboFixT\NTPBack.exe
2007-04-18 20:39 466 --------- E:\Download\Symantec\ComboFix\ComboFixT\CFCleanUp.bat
2007-04-18 20:39 466 --------- E:\Download\Symantec\ComboFix\ComboFixT\CFCleanUp.bat
2007-04-18 20:39 466 --------- E:\Download\Symantec\ComboFix\ComboFixT\CFCleanUp.bat
2007-04-18 20:39 423 --------- E:\Download\Symantec\ComboFix\ComboFixT\MoveIt.bat
2007-04-18 20:39 423 --------- E:\Download\Symantec\ComboFix\ComboFixT\MoveIt.bat
2007-04-18 20:39 423 --------- E:\Download\Symantec\ComboFix\ComboFixT\MoveIt.bat
2007-04-18 20:39 42,860 --------- E:\Download\Symantec\ComboFix\ComboFixT\ntp.exe
2007-04-18 20:39 42,860 --------- E:\Download\Symantec\ComboFix\ComboFixT\ntp.exe
2007-04-18 20:39 42,860 --------- E:\Download\Symantec\ComboFix\ComboFixT\ntp.exe
2007-04-18 20:39 3,410 --------- E:\Download\Symantec\ComboFix\ComboFixT\FixLSP.bat
2007-04-18 20:39 3,410 --------- E:\Download\Symantec\ComboFix\ComboFixT\FixLSP.bat
2007-04-18 20:39 3,410 --------- E:\Download\Symantec\ComboFix\ComboFixT\FixLSP.bat
2007-04-18 20:39 3,111 --a------ E:\Download\Symantec\ComboFix\ComboFixT\setpath.bat
2007-04-18 20:39 3,111 --a------ E:\Download\Symantec\ComboFix\ComboFixT\setpath.bat
2007-04-18 20:39 3,111 --a------ E:\Download\Symantec\ComboFix\ComboFixT\setpath.bat
2007-04-18 20:39 25,015 --a------ E:\Download\Symantec\ComboFix\ComboFixT\FIND3M.bat
2007-04-18 20:39 25,015 --a------ E:\Download\Symantec\ComboFix\ComboFixT\FIND3M.bat
2007-04-18 20:39 25,015 --a------ E:\Download\Symantec\ComboFix\ComboFixT\FIND3M.bat
2007-04-18 20:39 2,312 --------- E:\Download\Symantec\ComboFix\ComboFixT\Boot.bat
2007-04-18 20:39 2,312 --------- E:\Download\Symantec\ComboFix\ComboFixT\Boot.bat
2007-04-18 20:39 2,312 --------- E:\Download\Symantec\ComboFix\ComboFixT\Boot.bat
2007-04-18 20:39 2,102 --------- E:\Download\Symantec\ComboFix\ComboFixT\NTP.bat
2007-04-18 20:39 2,102 --------- E:\Download\Symantec\ComboFix\ComboFixT\NTP.bat
2007-04-18 20:39 2,102 --------- E:\Download\Symantec\ComboFix\ComboFixT\NTP.bat
2007-04-18 20:39 123,814 --a------ E:\Download\Symantec\ComboFix\ComboFixT\ComboFix.bat
2007-04-18 20:39 123,814 --a------ E:\Download\Symantec\ComboFix\ComboFixT\ComboFix.bat
2007-04-18 20:39 123,814 --a------ E:\Download\Symantec\ComboFix\ComboFixT\ComboFix.bat
2007-04-06 02:42 <DIR> d-------- E:\Gallery2
2007-04-06 02:42 <DIR> d-------- E:\Gallery2
2007-04-06 02:42 <DIR> d-------- E:\Gallery2
2007-04-06 02:42 <DIR> d-------- E:\Gallery2
2007-04-06 02:42 <DIR> d-------- E:\Gallery2
2007-04-06 02:42 <DIR> d-------- E:\Gallery2
2007-04-06 02:42 <DIR> d-------- E:\Gallery2
2007-04-06 02:42 <DIR> d-------- E:\Gallery2
2007-04-06 02:42 <DIR> d-------- E:\Gallery2
2007-04-06 02:42 <DIR> d-------- E:\Gallery2
2007-04-06 02:42 <DIR> d-------- E:\Gallery2
2007-04-06 02:42 <DIR> d-------- E:\Gallery2
2007-04-06 02:42 <DIR> d-------- E:\Gallery2
2007-04-06 02:42 <DIR> d-------- E:\Gallery2
2007-04-06 02:42 <DIR> d-------- E:\Gallery2
2007-04-06 02:42 <DIR> d-------- E:\Gallery2
2007-04-06 02:42 <DIR> d-------- E:\Gallery2
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-04-18 20:43 839 --a------ E:\Download\Symantec\ComboFix\ComboFixT\error.log
2007-04-18 20:43 839 --a------ E:\Download\Symantec\ComboFix\ComboFixT\error.log
2007-04-18 20:43 839 --a------ E:\Download\Symantec\ComboFix\ComboFixT\error.log
2007-04-18 20:43 6466 --a------ E:\Download\Symantec\ComboFix\ComboFixT\f3m0.cf
2007-04-18 20:43 4924 --a------ E:\Download\Symantec\ComboFix\ComboFixT\combofix.txt
2007-04-18 20:43 4924 --a------ E:\Download\Symantec\ComboFix\ComboFixT\combofix.txt
2007-04-18 20:43 4924 --a------ E:\Download\Symantec\ComboFix\ComboFixT\combofix.txt
2007-04-18 20:43 4575 --a------ E:\Download\Symantec\ComboFix\ComboFixT\30create2.cf
2007-04-18 20:43 4575 --a------ E:\Download\Symantec\ComboFix\ComboFixT\30create2.cf
2007-04-18 20:43 4575 --a------ E:\Download\Symantec\ComboFix\ComboFixT\30create2.cf
2007-04-18 20:43 395666 --a------ E:\Download\Symantec\ComboFix\ComboFixT\creg.cf
2007-04-18 20:43 395666 --a------ E:\Download\Symantec\ComboFix\ComboFixT\creg.cf
2007-04-18 20:43 395666 --a------ E:\Download\Symantec\ComboFix\ComboFixT\creg.cf
2007-04-18 20:43 237 --a------ E:\Download\Symantec\ComboFix\ComboFixT\catchme.log
2007-04-18 20:43 237 --a------ E:\Download\Symantec\ComboFix\ComboFixT\catchme.log
2007-04-18 20:43 237 --a------ E:\Download\Symantec\ComboFix\ComboFixT\catchme.log
2007-04-18 20:43 13599 --a------ E:\Download\Symantec\ComboFix\ComboFixT\f3m0.cf
2007-04-18 20:43 124 --a------ E:\Download\Symantec\ComboFix\ComboFixT\svctarget.cf
2007-04-18 20:43 124 --a------ E:\Download\Symantec\ComboFix\ComboFixT\svctarget.cf
2007-04-18 20:43 124 --a------ E:\Download\Symantec\ComboFix\ComboFixT\svctarget.cf
2007-04-18 20:43 10032 --a------ E:\Download\Symantec\ComboFix\ComboFixT\f3m0.cf
2007-04-18 20:40 0 --a------ E:\Download\Symantec\ComboFix\ComboFixT\d-del2a.cf
2007-04-18 20:40 0 --a------ E:\Download\Symantec\ComboFix\ComboFixT\d-del2a.cf
2007-04-18 20:40 0 --a------ E:\Download\Symantec\ComboFix\ComboFixT\d-del2a.cf
2007-04-18 20:39 7526 --a------ E:\Download\Symantec\ComboFix\ComboFixT\whitedir.cf
2007-04-18 20:39 7526 --a------ E:\Download\Symantec\ComboFix\ComboFixT\whitedir.cf
2007-04-18 20:39 7526 --a------ E:\Download\Symantec\ComboFix\ComboFixT\whitedir.cf
2007-04-18 20:39 507 --a------ E:\Download\Symantec\ComboFix\ComboFixT\net_svc.cf
2007-04-18 20:39 507 --a------ E:\Download\Symantec\ComboFix\ComboFixT\net_svc.cf
2007-04-18 20:39 507 --a------ E:\Download\Symantec\ComboFix\ComboFixT\net_svc.cf
2007-04-18 20:39 3314 --a------ E:\Download\Symantec\ComboFix\ComboFixT\dll_whitelist.cf
2007-04-18 20:39 3314 --a------ E:\Download\Symantec\ComboFix\ComboFixT\dll_whitelist.cf
2007-04-18 20:39 3314 --a------ E:\Download\Symantec\ComboFix\ComboFixT\dll_whitelist.cf
2007-04-18 20:39 197 --a------ E:\Download\Symantec\ComboFix\ComboFixT\appdatafolders.cf
2007-04-18 20:39 197 --a------ E:\Download\Symantec\ComboFix\ComboFixT\appdatafolders.cf
2007-04-18 20:39 197 --a------ E:\Download\Symantec\ComboFix\ComboFixT\appdatafolders.cf
2007-04-17 03:42 1536 --a------ E:\Download\Symantec\ComboFix\ComboFixT\md5.cf
2007-04-17 03:42 1536 --a------ E:\Download\Symantec\ComboFix\ComboFixT\md5.cf
2007-04-17 03:42 1536 --a------ E:\Download\Symantec\ComboFix\ComboFixT\md5.cf
2007-04-15 03:40 222 --------- E:\Download\Symantec\ComboFix\ComboFixT\v_combofix.cf
2007-04-15 03:40 222 --------- E:\Download\Symantec\ComboFix\ComboFixT\v_combofix.cf
2007-04-15 03:40 222 --------- E:\Download\Symantec\ComboFix\ComboFixT\v_combofix.cf
2007-04-10 03:21 14 --------- E:\Download\Symantec\ComboFix\ComboFixT\erunt.cf
2007-04-10 03:21 14 --------- E:\Download\Symantec\ComboFix\ComboFixT\erunt.cf
2007-04-10 03:21 14 --------- E:\Download\Symantec\ComboFix\ComboFixT\erunt.cf
2007-04-10 01:11 370 --------- E:\Download\Symantec\ComboFix\ComboFixT\whitedirb.cf
2007-04-10 01:11 370 --------- E:\Download\Symantec\ComboFix\ComboFixT\whitedirb.cf
2007-04-10 01:11 370 --------- E:\Download\Symantec\ComboFix\ComboFixT\whitedirb.cf
2007-04-10 01:09 103 --------- E:\Download\Symantec\ComboFix\ComboFixT\executables.cf
2007-04-10 01:09 103 --------- E:\Download\Symantec\ComboFix\ComboFixT\executables.cf
2007-04-10 01:09 103 --------- E:\Download\Symantec\ComboFix\ComboFixT\executables.cf
2007-04-10 01:08 2687 --------- E:\Download\Symantec\ComboFix\ComboFixT\whitelegacy.cf
2007-04-10 01:08 2687 --------- E:\Download\Symantec\ComboFix\ComboFixT\whitelegacy.cf
2007-04-10 01:08 2687 --------- E:\Download\Symantec\ComboFix\ComboFixT\whitelegacy.cf
2007-04-08 02:34 206 --------- E:\Download\Symantec\ComboFix\ComboFixT\notifykeys.cf
2007-04-08 02:34 206 --------- E:\Download\Symantec\ComboFix\ComboFixT\notifykeys.cf
2007-04-08 02:34 206 --------- E:\Download\Symantec\ComboFix\ComboFixT\notifykeys.cf
2007-04-08 02:32 1960 --------- E:\Download\Symantec\ComboFix\ComboFixT\def_safeboot.cf
2007-04-08 02:32 1960 --------- E:\Download\Symantec\ComboFix\ComboFixT\def_safeboot.cf
2007-04-08 02:32 1960 --------- E:\Download\Symantec\ComboFix\ComboFixT\def_safeboot.cf
2007-04-06 17:27 24064 --------- E:\Download\Symantec\ComboFix\ComboFixT\cut.cfexe
2007-04-06 17:27 24064 --------- E:\Download\Symantec\ComboFix\ComboFixT\cut.cfexe
2007-04-06 17:27 24064 --------- E:\Download\Symantec\ComboFix\ComboFixT\cut.cfexe
2007-04-06 17:27 24064 --------- E:\Download\Symantec\ComboFix\ComboFixT\cut.cfexe
2007-04-06 17:27 24064 --------- E:\Download\Symantec\ComboFix\ComboFixT\cut.cfexe
2007-04-06 17:27 24064 --------- E:\Download\Symantec\ComboFix\ComboFixT\cut.cfexe
2007-04-04 02:54 65536 --------- E:\Download\Symantec\ComboFix\ComboFixT\regbindump.cfexe
2007-04-04 02:54 65536 --------- E:\Download\Symantec\ComboFix\ComboFixT\regbindump.cfexe
2007-04-04 02:54 65536 --------- E:\Download\Symantec\ComboFix\ComboFixT\regbindump.cfexe
2007-04-04 02:54 65536 --------- E:\Download\Symantec\ComboFix\ComboFixT\regbindump.cfexe
2007-04-04 02:54 65536 --------- E:\Download\Symantec\ComboFix\ComboFixT\regbindump.cfexe
2007-04-04 02:54 65536 --------- E:\Download\Symantec\ComboFix\ComboFixT\regbindump.cfexe
2007-04-02 14:21 428032 --a------ E:\Download\Symantec\ComboFix\ComboFixT\swreg.cfexe
2007-04-02 14:21 428032 --a------ E:\Download\Symantec\ComboFix\ComboFixT\swreg.cfexe
2007-04-02 14:21 428032 --a------ E:\Download\Symantec\ComboFix\ComboFixT\swreg.cfexe
2007-04-02 14:21 428032 --a------ E:\Download\Symantec\ComboFix\ComboFixT\swreg.cfexe
2007-04-02 14:21 428032 --a------ E:\Download\Symantec\ComboFix\ComboFixT\swreg.cfexe
2007-04-02 14:21 428032 --a------ E:\Download\Symantec\ComboFix\ComboFixT\swreg.cfexe
2007-03-13 10:57 4090 --------- E:\Download\Symantec\ComboFix\ComboFixT\erunt.loc
2007-03-13 10:57 4090 --------- E:\Download\Symantec\ComboFix\ComboFixT\erunt.loc
2007-03-13 10:57 4090 --------- E:\Download\Symantec\ComboFix\ComboFixT\erunt.loc
2007-03-13 10:57 393216 --------- E:\Download\Symantec\ComboFix\ComboFixT\erunt.cfexe
2007-03-13 10:57 393216 --------- E:\Download\Symantec\ComboFix\ComboFixT\erunt.cfexe
2007-03-13 10:57 393216 --------- E:\Download\Symantec\ComboFix\ComboFixT\erunt.cfexe
2007-03-13 10:57 393216 --------- E:\Download\Symantec\ComboFix\ComboFixT\erunt.cfexe
2007-03-13 10:57 393216 --------- E:\Download\Symantec\ComboFix\ComboFixT\erunt.cfexe
2007-03-13 10:57 393216 --------- E:\Download\Symantec\ComboFix\ComboFixT\erunt.cfexe
2007-03-13 10:57 3275 --------- E:\Download\Symantec\ComboFix\ComboFixT\erdntwin.loc
2007-03-13 10:57 3275 --------- E:\Download\Symantec\ComboFix\ComboFixT\erdntwin.loc
2007-03-13 10:57 3275 --------- E:\Download\Symantec\ComboFix\ComboFixT\erdntwin.loc
2007-03-13 10:57 2815 --------- E:\Download\Symantec\ComboFix\ComboFixT\erdntdos.loc
2007-03-13 10:57 2815 --------- E:\Download\Symantec\ComboFix\ComboFixT\erdntdos.loc
2007-03-13 10:57 2815 --------- E:\Download\Symantec\ComboFix\ComboFixT\erdntdos.loc
2007-03-13 10:57 163328 --------- E:\Download\Symantec\ComboFix\ComboFixT\erdnt.e_e
2007-03-13 10:57 163328 --------- E:\Download\Symantec\ComboFix\ComboFixT\erdnt.e_e
2007-03-13 10:57 163328 --------- E:\Download\Symantec\ComboFix\ComboFixT\erdnt.e_e
2007-03-08 03:40 28672 --a------ E:\Download\Symantec\ComboFix\ComboFixT\4321.cfexe
2007-03-08 03:40 28672 --a------ E:\Download\Symantec\ComboFix\ComboFixT\4321.cfexe
2007-03-08 03:40 28672 --a------ E:\Download\Symantec\ComboFix\ComboFixT\4321.cfexe
2007-03-08 03:40 28672 --a------ E:\Download\Symantec\ComboFix\ComboFixT\4321.cfexe
2007-03-08 03:40 28672 --a------ E:\Download\Symantec\ComboFix\ComboFixT\4321.cfexe
2007-03-08 03:40 28672 --a------ E:\Download\Symantec\ComboFix\ComboFixT\4321.cfexe
2007-01-30 00:07 51200 --------- E:\Download\Symantec\ComboFix\ComboFixT\dumphive.cfexe
2007-01-30 00:07 51200 --------- E:\Download\Symantec\ComboFix\ComboFixT\dumphive.cfexe
2007-01-30 00:07 51200 --------- E:\Download\Symantec\ComboFix\ComboFixT\dumphive.cfexe
2007-01-30 00:07 51200 --------- E:\Download\Symantec\ComboFix\ComboFixT\dumphive.cfexe
2007-01-30 00:07 51200 --------- E:\Download\Symantec\ComboFix\ComboFixT\dumphive.cfexe
2007-01-30 00:07 51200 --------- E:\Download\Symantec\ComboFix\ComboFixT\dumphive.cfexe
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{53707962-6F74-2D53-2644-206D7942484F} C:\PROGRA~1\SPYBOT~1\SDHelper.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} C:\Program Files\Java\jre1.6.0\bin\ssv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\""
"FTP Server"="C:\\Tools\\FTPSER~1\\ftpserv.exe"
"CmUsbSound"="RunDll32 cmcnfgu.cpl,CMICtrlWnd"
"DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"ISUSPM Startup"="\"c:\\Program Files\\Common Files\\InstallShield\\UpdateService\\isuspm.exe\" -startup"
"ISUSScheduler"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start"
"NeroFilterCheck"="\"C:\\Program Files\\Common Files\\Ahead\\Lib\\NeroCheck.exe\""
"DB2COPY1 - db2systray.exe DB2"="\"C:\\PROGRA~1\\IBM\\SQLLIB\\BIN\\db2systray.exe\" DB2"
"hldrrr"="C:\\WINDOWS\\system32\\hldrrr.exe"
"Spybot"="C:\\Program Files\\Spybot - Search Destroy\\SpybotSD.exe /autoimmunize /autoclose /minimized /taskbarhide"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"ISUSPM"="\"c:\\Program Files\\Common Files\\InstallShield\\UpdateService\\isuspm.exe\" -scheduler"
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="\"C:\\Program Files\\Common Files\\Ahead\\Lib\\NMBgMonitor.exe\""
"hldrrr"="C:\\WINDOWS\\system32\\hldrrr.exe"
"drvsyskit"="C:\\Documents and Settings\\Administrator\\Application Data\\hidires\\hidr.exe"
"german.exe"="C:\\WINDOWS\\system32\\wintems.exe"
"SpybotSD TeaTimer"="C:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"tscuninstall"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,65,6d,\
33,32,5c,74,73,63,75,70,67,72,64,2e,65,78,65,00
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"=dword:00000000
"scforceoption"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Notification Packages REG_MULTI_SZ RASSFM\0KDCSVC\0WDIGEST\0scecli\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
SafeBoot registry key needs to be repaired. This machine cannot enter Safe Mode.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0WinHttpAutoProxySvc\0W32Time\0\0
NetworkService REG_MULTI_SZ 6to4\0DHCP\0DnsCache\0\0
WinErr REG_MULTI_SZ ERsvc\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
tapisrv REG_MULTI_SZ Tapisrv\0\0
regsvc REG_MULTI_SZ RemoteRegistry\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
swprv REG_MULTI_SZ swprv\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0\0
hklm\software\Microsoft\Windows NT\CurrentVersion\Svchost *netsvcs*
AeLookupSvc
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\EIBSetDateTime.job
C:\WINDOWS\tasks\EIBWetterAlarm.job
C:\WINDOWS\tasks\My Documents Backup.job
C:\WINDOWS\tasks\Router Reboot.job
C:\WINDOWS\tasks\Router Reconnect leebg.selfip.com.job
C:\WINDOWS\tasks\Router Reconnect.job
C:\WINDOWS\tasks\Systemdaten Backup.job
********************************************************************
catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-04-18 20:44:14
E:\ComboFix-quarantined-files.txt ... 07-04-18 20:44