soooo....fertig!
ComboFix 09-05-24.07 - Pawel Wendt 25.05.2009 18:03.3 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.49.1031.18.2046.1341 [GMT 2:00]
ausgeführt von:: c:\users\Pawel Wendt\Desktop\ComboFix.exe
Benutzte Befehlsschalter :: c:\users\Pawel Wendt\Desktop\CFScript.txt
SP: Windows-Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Resident AV is active
file zipped: c:\users\Pawel Wendt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\santa.bat
file zipped: c:\users\Pawel Wendt\AppData\Roaming\soup.exe
file zipped: c:\users\Pawel Wendt\AppData\Roaming\vcshost.exe
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\Pawel Wendt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\santa.bat
c:\users\Pawel Wendt\AppData\Roaming\soup.exe
c:\users\Pawel Wendt\AppData\Roaming\vcshost.exe
c:\windows\TEMP\logishrd\LVPrcInj01.dll
.
((((((((((((((((((((((( Dateien erstellt von 2009-04-25 bis 2009-05-25 ))))))))))))))))))))))))))))))
.
2009-05-25 16:05 . 2009-05-25 16:07 -------- d-----w c:\users\Pawel Wendt\AppData\Local\temp
2009-05-25 14:01 . 2009-05-25 14:01 -------- d-----w c:\users\Pawel Wendt\AppData\Roaming\Malwarebytes
2009-05-25 13:25 . 2009-05-25 13:26 -------- d-----w c:\users\Pawel Wendt\AppData\Roaming\GetRightToGo
2009-05-25 13:09 . 2009-04-06 13:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-05-25 13:09 . 2009-04-06 13:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-25 13:09 . 2009-05-25 13:09 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-05-25 13:09 . 2009-05-25 13:09 -------- d-----w c:\programdata\Malwarebytes
2009-05-23 08:38 . 2009-05-25 14:00 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-05-22 14:55 . 2009-05-22 14:57 -------- d-----w c:\users\Pawel Wendt\AppData\Roaming\Command & Conquer 3 Tiberium Wars
2009-05-22 14:14 . 2009-05-25 14:34 -------- d-----w c:\program files\7-Zip
2009-05-22 13:48 . 2009-05-22 13:48 -------- d--h--r c:\users\Pawel Wendt\AppData\Roaming\SecuROM
2009-05-22 13:48 . 2009-05-22 13:48 98304 ----a-w c:\windows\system32CmdLineExt.dll
2009-05-22 13:30 . 2009-05-06 18:06 4784464 ----a-w c:\programdata\Microsoft\Windows Defender\Definition Updates\{8867E21A-1364-40ED-A7B3-791DB6787F04}\mpengine.dll
2009-05-22 13:27 . 2009-05-22 13:27 -------- d-----w c:\program files\Alcohol Soft
2009-05-22 13:25 . 2009-05-22 13:25 721904 ----a-w c:\windows\system32\drivers\sptd.sys
2009-05-14 17:43 . 2009-05-14 17:43 -------- d-----w c:\users\Pawel Wendt\AppData\Local\PowerDVDCox
2009-05-14 17:43 . 2009-05-14 17:43 -------- d-----w c:\users\Pawel Wendt\AppData\Local\PowerDVDCinema
2009-05-14 17:40 . 2009-05-14 17:40 -------- d-----w c:\users\Public\CyberLink
2009-05-14 17:39 . 2009-05-14 17:39 -------- d-----w c:\users\Pawel Wendt\AppData\Roaming\vlc
2009-05-14 17:33 . 2009-05-14 17:33 -------- d-----w c:\program files\Common Files\CyberLink
2009-05-14 17:29 . 2009-05-14 18:16 29480 ----a-w c:\windows\system32\msxml3a.dll
2009-05-14 17:29 . 2009-05-18 23:39 53319 ----a-w c:\programdata\TEMP\{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}\PostBuild.exe
2009-05-14 12:33 . 2009-05-14 12:33 -------- d-----w c:\windows\Log
2009-05-14 12:31 . 2009-05-14 12:31 -------- d-----w c:\program files\Common Files\Deterministic Networks
2009-05-14 12:31 . 2009-05-14 12:31 -------- d-----w c:\program files\Cisco Systems
2009-05-13 17:51 . 2009-05-14 12:29 -------- d-----w c:\program files\SpybotNeu
2009-05-09 18:00 . 2008-07-08 11:27 166400 ------w c:\windows\system32\CTOPT352.dll
2009-05-09 18:00 . 2008-07-08 09:50 61440 ------w c:\windows\system32\CTChkAud.dll
2009-05-09 17:05 . 2008-02-12 09:34 16618970 ------w c:\programdata\Creative\Media Toolbox6\AddOnPack.exe
2009-05-09 17:00 . 2009-05-09 17:03 37406376 ----a-w c:\programdata\Creative\Software Update\cache\Creative MediaSource 5 Player_Organizer 5.25.02__\CMS5_PCAPP_LB_5_25_02.exe
2009-05-09 17:00 . 2009-05-09 17:00 6657680 ----a-w c:\programdata\Creative\Software Update\cache\Creative SoundFont Bank Manager 3.21.00__\SFBM_PCAPP_LB_3_21_00.exe
2009-05-09 16:55 . 2009-05-09 16:59 62234496 ----a-w c:\programdata\Creative\Software Update\cache\Creative Console Launcher 2.61.09__\CSL_PCAPP_LB_2_61_09.exe
2009-05-09 16:55 . 2009-05-09 16:55 6280712 ----a-w c:\programdata\Creative\Software Update\cache\DTS Connect Pack for Sound Blaster X-Fi Titanium series 1.03.00__\DTS_PCAPP_LB_1_03_00.exe
2009-05-09 16:54 . 2009-05-09 16:55 8512328 ----a-w c:\programdata\Creative\Software Update\cache\Creative ALchemy 1.25.10__\ALMY_PCVTAPP_LB_1_25_10.exe
2009-05-09 16:50 . 2009-05-09 16:54 70681997 ----a-w c:\programdata\Creative\Software Update\cache\Creative Console Launcher 2.60.29__\CSL_PCAPP_LB_2_60_29.exe
2009-05-09 16:47 . 2009-05-09 16:50 30892544 ----a-w c:\programdata\Creative\Software Update\cache\Creative 3D MIDI Player 1.11.00__\3DMP_PCAPP_LB_1_11_00.exe
2009-05-09 16:46 . 2009-05-09 16:47 22973672 ----a-w c:\programdata\Creative\Software Update\cache\Creative Diagnostics 5.11.00__\DNT_PCAPP_LB_5_11_00.exe
2009-05-09 16:42 . 2009-05-09 16:45 56988896 ----a-w c:\programdata\Creative\Software Update\cache\Creative Media Toolbox Trial 6.02.09__\MTB6_PCAPP_LB_6_02_09.exe
2009-05-09 16:41 . 2009-05-09 16:42 12846328 ----a-w c:\programdata\Creative\Software Update\cache\Creative WaveStudio 7.11.00__\WAVESTD_PCAPP_LB_7_11_00.exe
2009-05-06 11:14 . 2009-05-06 11:14 32200 ----a-w c:\windows\system32\drivers\HookCentre.sys
2009-04-30 16:36 . 2009-05-24 07:23 -------- d-----w c:\programdata\DVD Shrink
2009-04-30 16:34 . 2009-04-30 16:34 -------- d-----w c:\users\Pawel Wendt\AppData\Roaming\HandBrake
2009-04-30 15:19 . 2009-04-30 15:19 24576 ----a-w c:\users\Pawel Wendt\AppData\Local\cp_setup_assist.exe
2009-04-27 08:00 . 2009-04-27 08:00 56 ---ha-w c:\windows\system32\ezsidmv.dat
2009-04-27 08:00 . 2009-05-21 07:17 -------- d-----w c:\users\Pawel Wendt\AppData\Roaming\skypePM
2009-04-27 07:59 . 2009-05-21 07:31 -------- d-----w c:\users\Pawel Wendt\AppData\Roaming\Skype
2009-04-27 07:58 . 2009-04-27 07:58 -------- d-----w c:\program files\Common Files\Skype
2009-04-27 07:58 . 2009-04-27 07:58 -------- d-----r c:\program files\Skype
2009-04-27 07:58 . 2009-04-27 07:58 -------- d-----w c:\programdata\Skype
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-25 16:08 . 2009-03-30 09:17 -------- d-----w c:\programdata\Babylon
2009-05-25 16:06 . 2008-11-19 14:27 0 ----a-w c:\windows\system32\drivers\lvuvc.hs
2009-05-25 14:39 . 2006-11-02 15:33 618204 ----a-w c:\windows\system32\perfh007.dat
2009-05-25 14:39 . 2006-11-02 15:33 122442 ----a-w c:\windows\system32\perfc007.dat
2009-05-25 14:00 . 2008-11-19 23:29 -------- d-----w c:\programdata\Spybot - Search & Destroy
2009-05-25 12:02 . 2008-11-19 23:34 -------- d-----w c:\program files\StarMoney 6.0 S-Edition
2009-05-22 22:26 . 2008-12-03 11:56 -------- d-----w c:\program files\Common Files\Steam
2009-05-22 12:54 . 2009-03-12 22:41 -------- d-----w c:\programdata\Roxio
2009-05-19 20:05 . 2008-12-11 23:08 -------- d-----w c:\users\Pawel Wendt\AppData\Roaming\teamspeak2
2009-05-19 10:32 . 2008-11-19 14:57 -------- d-----w c:\users\Pawel Wendt\AppData\Roaming\Azureus
2009-05-18 23:54 . 2008-11-19 14:20 -------- d--h--w c:\program files\InstallShield Installation Information
2009-05-14 18:36 . 2008-11-26 21:15 -------- d-----w c:\programdata\CyberLink
2009-05-14 17:43 . 2008-11-26 21:33 -------- d-----w c:\users\Pawel Wendt\AppData\Roaming\CyberLink
2009-05-14 15:39 . 2009-04-02 19:33 -------- d-----w c:\users\Pawel Wendt\AppData\Roaming\Creative
2009-05-13 10:53 . 2008-11-19 22:40 -------- d-----w c:\programdata\Microsoft Help
2009-05-13 10:52 . 2006-11-02 11:18 -------- d-----w c:\program files\Windows Mail
2009-05-09 18:38 . 2009-04-02 19:27 -------- d-----w c:\programdata\Creative
2009-05-09 18:05 . 2009-04-02 19:25 -------- d--h--w c:\program files\Creative Installation Information
2009-05-09 18:02 . 2009-04-02 19:19 -------- d-----w c:\program files\Creative
2009-05-07 06:35 . 2008-11-20 01:05 29128 ----a-w c:\windows\system32\drivers\GRD.sys
2009-05-06 11:16 . 2008-11-19 15:40 -------- d-----w c:\programdata\G DATA
2009-05-06 11:14 . 2008-11-19 15:40 40392 ----a-w c:\windows\system32\drivers\gdwfpcd32.sys
2009-05-06 11:14 . 2008-11-19 15:40 -------- d-----w c:\program files\Common Files\G DATA
2009-05-06 11:14 . 2008-11-19 15:40 -------- d-----w c:\program files\G DATA
2009-04-29 09:05 . 2008-11-19 13:39 144528 ----a-w c:\users\Pawel Wendt\AppData\Local\GDIPFONTCACHEV1.DAT
2009-04-29 08:57 . 2008-11-19 22:43 -------- d-----w c:\program files\Microsoft Works
2009-04-24 17:10 . 2009-03-30 09:17 -------- d-----w c:\users\Pawel Wendt\AppData\Roaming\Babylon
2009-04-24 16:47 . 2009-04-24 16:46 -------- d-----w c:\program files\Teamspeak2_RC2
2009-04-23 09:21 . 2008-11-19 14:57 -------- d-----w c:\program files\Vuze
2009-04-17 21:54 . 2009-04-17 21:54 -------- d-----w c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-17 21:54 . 2009-04-17 21:54 -------- d-----w c:\program files\iTunes
2009-04-17 21:54 . 2009-04-17 21:54 -------- d-----w c:\program files\iPod
2009-04-17 21:54 . 2008-11-19 23:25 -------- d-----w c:\program files\Common Files\Apple
2009-04-17 21:51 . 2009-04-17 21:51 75048 ----a-w c:\programdata\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
2009-04-06 13:09 . 2008-11-19 14:57 -------- d-----w c:\program files\Java
2009-04-03 13:19 . 2006-11-02 12:37 -------- d-----w c:\program files\Windows Sidebar
2009-04-03 13:07 . 2008-11-19 15:40 50632 ----a-w c:\windows\system32\drivers\MiniIcpt.sys
2009-04-02 21:57 . 2009-04-02 21:57 -------- d-----w c:\program files\MozBackup
2009-04-02 20:11 . 2009-04-02 19:24 413696 ----a-w c:\windows\system32\wrap_oal.dll
2009-04-02 20:11 . 2009-04-02 19:24 110592 ----a-w c:\windows\system32\OpenAL32.dll
2009-04-02 19:30 . 2009-04-02 19:20 -------- d-----w c:\program files\Common Files\Creative Labs Shared
2009-04-02 19:25 . 2009-04-02 19:25 -------- d-----w c:\program files\Common Files\Creative
2009-04-02 19:24 . 2009-04-02 19:24 -------- d-----w c:\program files\OpenAL
2009-04-02 19:20 . 2009-04-02 19:20 -------- d-----w c:\programdata\Creative Labs
2009-04-01 19:22 . 2009-04-01 19:22 -------- d-----w c:\program files\iLinc
2009-03-26 09:24 . 2008-12-18 16:49 604416 ----a-w c:\windows\system32\TUProgSt.exe
2009-03-26 09:24 . 2009-03-26 09:24 360704 ----a-w c:\windows\system32\TuneUpDefragService.exe
2009-03-20 14:01 . 2009-03-26 09:24 17152 ----a-w c:\windows\system32\authuitu.dll
2009-03-20 14:01 . 2009-03-26 09:24 28416 ----a-w c:\windows\system32\uxtuneup.dll
2009-03-19 14:32 . 2009-04-17 21:54 23400 ----a-w c:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-19 14:32 . 2009-03-19 14:32 23400 ----a-w c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
2009-03-17 03:38 . 2009-04-17 21:02 13824 ----a-w c:\windows\system32\apilogen.dll
2009-03-17 03:38 . 2009-04-17 21:02 24064 ----a-w c:\windows\system32\amxread.dll
2009-03-16 21:33 . 2009-03-16 21:33 4361216 ----a-w c:\windows\system32\drivers\atikmdag.sys
2009-03-16 20:28 . 2009-03-16 20:28 442368 ----a-w c:\windows\system32\ATIDEMGX.dll
2009-03-16 20:27 . 2009-03-16 20:27 290816 ----a-w c:\windows\system32\atieclxx.exe
2009-03-16 20:27 . 2009-03-16 20:27 180224 ----a-w c:\windows\system32\atiesrxx.exe
2009-03-16 20:26 . 2008-10-29 02:20 159744 ----a-w c:\windows\system32\atitmmxx.dll
2009-03-16 20:25 . 2008-10-29 02:20 348160 ----a-w c:\windows\system32\atipdlxx.dll
2009-03-16 20:25 . 2009-03-16 20:25 274432 ----a-w c:\windows\system32\Oemdspif.dll
2009-03-16 20:25 . 2009-03-16 20:25 11776 ----a-w c:\windows\system32\atimuixx.dll
2009-03-16 20:25 . 2009-03-16 20:25 43520 ----a-w c:\windows\system32\ati2edxx.dll
2009-03-16 20:21 . 2009-03-16 20:21 2381312 ----a-w c:\windows\system32\atidxx32.dll
2009-03-16 20:11 . 2008-10-29 02:03 3837440 ----a-w c:\windows\system32\atiumdag.dll
2009-03-16 19:57 . 2009-03-16 19:57 11520000 ----a-w c:\windows\system32\atioglxx.dll
2009-03-16 19:53 . 2008-10-29 01:41 4950528 ----a-w c:\windows\system32\atiumdva.dll
2009-03-16 19:41 . 2009-03-16 19:41 51712 ----a-w c:\windows\system32\amdpcom32.dll
2009-03-16 19:41 . 2009-03-16 19:41 51712 ----a-w c:\windows\system32\atimpc32.dll
2009-03-16 19:41 . 2009-03-16 19:41 151552 ----a-w c:\windows\system32\atiadlxx.dll
2009-03-16 19:36 . 2009-03-16 19:36 53248 ----a-w c:\windows\system32\aticalrt.dll
2009-03-16 19:36 . 2009-03-16 19:36 53248 ----a-w c:\windows\system32\aticalcl.dll
2009-03-16 19:35 . 2009-03-16 19:35 3272704 ----a-w c:\windows\system32\aticaldd.dll
2009-03-16 19:27 . 2009-03-16 19:27 53248 ----a-w c:\windows\system32\drivers\ati2erec.dll
2009-03-09 03:19 . 2008-11-19 14:57 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-08 11:34 . 2009-04-29 08:52 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 11:34 . 2009-04-29 08:52 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 11:33 . 2009-04-29 08:52 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 11:33 . 2009-04-29 08:52 109056 ----a-w c:\windows\system32\iesysprep.dll
2009-03-08 11:33 . 2009-04-29 08:52 109568 ----a-w c:\windows\system32\PDMSetup.exe
2009-03-08 11:33 . 2009-04-29 08:52 132608 ----a-w c:\windows\system32\ieUnatt.exe
2009-03-08 11:33 . 2009-04-29 08:52 107520 ----a-w c:\windows\system32\RegisterIEPKEYs.exe
2009-03-08 11:33 . 2009-04-29 08:52 107008 ----a-w c:\windows\system32\SetIEInstalledDate.exe
2009-03-08 11:33 . 2009-04-29 08:52 103936 ----a-w c:\windows\system32\SetDepNx.exe
2009-03-08 11:33 . 2009-04-29 08:52 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 11:32 . 2009-04-29 08:52 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 11:32 . 2009-04-29 08:52 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 11:32 . 2009-04-29 08:52 66560 ----a-w c:\windows\system32\wextract.exe
2009-03-08 11:32 . 2009-04-29 08:52 169472 ----a-w c:\windows\system32\iexpress.exe
2009-03-08 11:31 . 2009-04-29 08:52 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 11:31 . 2009-04-29 08:52 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 11:31 . 2009-04-29 08:52 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 11:22 . 2009-04-29 08:52 156160 ----a-w c:\windows\system32\msls31.dll
2009-03-05 22:59 . 2009-03-05 22:59 36864 ----a-w c:\windows\system32\drivers\usbaapl.sys
2009-03-05 22:59 . 2009-03-05 22:59 1900544 ----a-w c:\windows\system32\usbaaplrc.dll
2009-03-03 19:56 . 2009-03-03 19:56 118784 ----a-w c:\windows\system32\atibtmon.exe
2009-03-03 04:46 . 2009-04-17 21:03 3599328 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-03-03 04:46 . 2009-04-17 21:03 3547632 ----a-w c:\windows\system32\ntoskrnl.exe
2009-03-03 04:39 . 2009-04-17 21:03 183296 ----a-w c:\windows\system32\sdohlp.dll
2009-03-03 04:39 . 2009-04-17 21:03 551424 ----a-w c:\windows\system32\rpcss.dll
2009-03-03 04:39 . 2009-04-17 21:03 26112 ----a-w c:\windows\system32\printfilterpipelineprxy.dll
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2008-11-12 6687264]
"Launch LCDMon"="c:\program files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2007-12-13 2051096]
"Launch LGDCore"="c:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2007-12-13 2095640]
"Babylon Client"="c:\program files\Babylon\Babylon-Pro\Babylon.exe" [2009-03-31 3563232]
"G DATA AntiVirus Trayapplication"="c:\program files\G DATA\AntiVirus\AVKTray\AVKTray.exe" [2009-03-11 920136]
"VolPanel"="c:\program files\Creative\Volume Panel\VolPanlu.exe" [2008-08-06 233576]
"CTxfiHlp"="CTXFIHLP.EXE" - c:\windows\System32\Ctxfihlp.exe [2009-02-19 24576]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
VPN Client.lnk - c:\windows\Installer\{4C271126-C295-4828-A901-5910AE0C258B}\Icon3E5562ED7.ico [2009-5-14 6144]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" /hide
"LLPush"=c:\program files\iLinc\Client77\bin\LLPush.exe
"ISUSPM Startup"=c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" -start
"UpdReg"=c:\windows\UpdReg.EXE
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{9FA66A57-A66A-49FE-8615-3AB708E96BC4}"= UDP:c:\program files\Java\jre6\bin\javaw.exe:javaw
"{D67A2F44-5AED-4FA6-A41D-782151FA031B}"= TCP:c:\program files\Java\jre6\bin\javaw.exe:javaw
"TCP Query User{D7DF9E16-514A-4117-AE98-8A1D7C4B0E34}c:\\program files\\vuze\\azureus.exe"= UDP:c:\program files\vuze\azureus.exe:Azureus
"UDP Query User{C0975964-7C08-44F9-8544-B2F218540D9F}c:\\program files\\vuze\\azureus.exe"= TCP:c:\program files\vuze\azureus.exe:Azureus
"{45B063AC-C308-43DB-93C8-01DB28845DF5}"= UDP:42949:Vuze
"{465998AC-F2A6-4229-8EF9-8BDE84BBC2D8}"= TCP:42949:Vuz2
"TCP Query User{EA96257B-0339-41BF-ADA1-4C594D14FE27}e:\\meine empfangenen dateien\\ws_ftp\\ws_ftp\\ws_ftp95.exe"= UDP:e:\meine empfangenen dateien\ws_ftp\ws_ftp\ws_ftp95.exe:WS_FTP 95
"UDP Query User{CE3F8675-9DE7-414B-9934-80F28EEC5464}e:\\meine empfangenen dateien\\ws_ftp\\ws_ftp\\ws_ftp95.exe"= TCP:e:\meine empfangenen dateien\ws_ftp\ws_ftp\ws_ftp95.exe:WS_FTP 95
"{B8F1389E-EB22-4612-A714-6320FB478C60}"= UDP:c:\program files\Pinnacle\Studio 10\programs\RM.exe:Render Manager
"{51A8AA01-BC09-45DE-9A17-8CE208DDD321}"= TCP:c:\program files\Pinnacle\Studio 10\programs\RM.exe:Render Manager
"{F326ECED-F0AC-4230-9FB1-61ABA715FA33}"= UDP:c:\program files\Pinnacle\Studio 10\programs\Studio.exe:Studio
"{783483B0-355A-492B-AE6F-6A0AA0C2B436}"= TCP:c:\program files\Pinnacle\Studio 10\programs\Studio.exe:Studio
"{09B651A9-6342-44DB-A5D4-3E582C861AAD}"= UDP:c:\program files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe

MSRegisterFile
"{2F12A67C-C94E-4B88-B5F7-D031F07C9315}"= TCP:c:\program files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe

MSRegisterFile
"{70F7EC0C-D635-4128-B22C-D1AF9DF74049}"= UDP:c:\program files\Pinnacle\Studio 10\programs\umi.exe:umi
"{F6518062-B55B-4CA4-AB80-21906252F949}"= TCP:c:\program files\Pinnacle\Studio 10\programs\umi.exe:umi
"TCP Query User{709FAC36-D2FD-4C47-A96E-13AC3ED3E176}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{B7592DA6-4E0F-4127-A578-EE36E2432832}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"{69EDAB52-83CE-4CE9-BCE6-C1DBF977A684}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"TCP Query User{C55C6C34-E344-41EA-AF95-3EFF1B4FCEFD}c:\\games\\steam\\steamapps\\coldpain_com\\day of defeat source\\hl2.exe"= UDP:c:\games\steam\steamapps\coldpain_com\day of defeat source\hl2.exe:hl2
"UDP Query User{35E6AF55-192F-44A6-A332-067B4D0CB3D9}c:\\games\\steam\\steamapps\\coldpain_com\\day of defeat source\\hl2.exe"= TCP:c:\games\steam\steamapps\coldpain_com\day of defeat source\hl2.exe:hl2
"{497EFFFE-C710-4504-9189-DBCF6466A47D}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-3.0.8.9464-to-3.0.8.9506-deDE-downloader.exe:Blizzard Downloader
"{FF194993-07C1-4FC5-A99D-48BD40E0281E}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-3.0.8.9464-to-3.0.8.9506-deDE-downloader.exe:Blizzard Downloader
"{15B8B200-765B-403C-8A22-943E4C8C0F95}"= UDP:3724:Blizzard Downloader: 3724
"{4A57AE41-EA8D-457E-AC08-8C02B0010F98}"= UDP:c:\program files\Ubisoft\Related Designs\Anno 1404 Closed Beta\Anno4.exe:Anno 1404 Closed Beta
"{2828B22F-0C52-428F-B700-A53C8A779F2B}"= TCP:c:\program files\Ubisoft\Related Designs\Anno 1404 Closed Beta\Anno4.exe:Anno 1404 Closed Beta
"{93DEAD58-4E0E-4B6E-9D51-4E6E65C438DE}"= UDP:c:\program files\Ubisoft\Related Designs\Anno 1404 Closed Beta\Reporter.exe:Anno 1404 Closed Beta Reporter
"{3629A5A9-FFF3-413C-816B-1FE18B70C94F}"= TCP:c:\program files\Ubisoft\Related Designs\Anno 1404 Closed Beta\Reporter.exe:Anno 1404 Closed Beta Reporter
"{96CC7A26-40B2-497A-8DE8-145791C86278}"= UDP:c:\program files\Ubisoft\Related Designs\Anno 1404 Closed Beta\TagesClient.exe:Anno 1404 Tages Client
"{FD90FFE8-1B0F-40CE-A27C-4FB11BED3950}"= TCP:c:\program files\Ubisoft\Related Designs\Anno 1404 Closed Beta\TagesClient.exe:Anno 1404 Tages Client
"TCP Query User{DC34E972-0CD0-4700-A0A5-CD3BC835B3BF}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{F1AEE06E-69A2-47B2-82D2-57E9645AA2B4}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{B006C9C9-F31E-4E0E-B775-C7AFC78674AD}c:\\games\\steam\\steamapps\\coldpain_com\\team fortress 2\\hl2.exe"= UDP:c:\games\steam\steamapps\coldpain_com\team fortress 2\hl2.exe:hl2
"UDP Query User{C0B3AD76-F483-46F6-A14D-FBAA72089821}c:\\games\\steam\\steamapps\\coldpain_com\\team fortress 2\\hl2.exe"= TCP:c:\games\steam\steamapps\coldpain_com\team fortress 2\hl2.exe:hl2
"TCP Query User{E08BDC54-1EBB-459F-A37B-F08E81FA7DA0}c:\\games\\steam\\steamapps\\coldpain_com\\opposing force\\hl.exe"= UDP:c:\games\steam\steamapps\coldpain_com\opposing force\hl.exe:Half-Life Launcher
"UDP Query User{5F472325-EC71-4561-B889-80CC989B2FEA}c:\\games\\steam\\steamapps\\coldpain_com\\opposing force\\hl.exe"= TCP:c:\games\steam\steamapps\coldpain_com\opposing force\hl.exe:Half-Life Launcher
"{AEB2B52C-3E8D-424F-B1E7-EB4680E1BF01}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{C734AD0B-F5E4-4081-A005-0B37B17DF143}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"TCP Query User{72D26C44-E4B9-4D37-A8CE-CC14D5996FF8}c:\\program files\\quicktime\\quicktimeplayer.exe"= UDP:c:\program files\quicktime\quicktimeplayer.exe:QuickTime Player
"UDP Query User{4C8C08BD-6FDE-4D29-BAF1-F4C0CF43F71B}c:\\program files\\quicktime\\quicktimeplayer.exe"= TCP:c:\program files\quicktime\quicktimeplayer.exe:QuickTime Player
"{AD678005-1058-413D-B943-628EC2351711}"= UDP:5353:Adobe CSI CS4
"{3396BD38-226D-4799-9C09-0BF0821AFB62}"= UDP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{D93AC4B0-D831-439B-9696-63024097000D}"= TCP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{18CB6A02-B6A3-4F05-A03A-54E451137881}"= Disabled:UDP:c:\program files\TuneUp Utilities 2009\Integrator.exe:TuneUp Utilities 2009
"{02ACE406-BE6C-4840-AA88-4A87036219FE}"= Disabled:TCP:c:\program files\TuneUp Utilities 2009\Integrator.exe:TuneUp Utilities 2009
"{A5699D27-8A4F-41FC-B94D-BF631BD6E845}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-3.0.9.9551-to-3.1.0.9767-deDE-downloader.exe:Blizzard Downloader
"{C8919076-5273-40BF-8C0C-9C52B3E23C63}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-3.0.9.9551-to-3.1.0.9767-deDE-downloader.exe:Blizzard Downloader
"{37CBB8DD-301A-482E-AEB3-FE99071A4DFD}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{2D066C0B-1886-4A26-9169-FA3377DDFA31}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{A33E0571-47F2-48B0-A80B-1956F62B4B5F}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{1CB12BE4-15A6-4BEB-925F-0C414442DA19}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{839C12DF-C720-43D3-AA3A-130E4A802460}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{A906D5EC-D0A5-4C6A-BDAB-B3B1787F13D8}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{A3D31F9A-6C56-448D-B9D7-17C2B59B8C67}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{7AC2B63A-0D32-42A1-9098-3A7DE539E9F3}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{5C37E0DC-7001-4B02-96B1-72C76E0E5E8D}"= c:\program files\Skype\Phone\Skype.exe:Skype
"TCP Query User{82B53430-35B1-464D-B6DE-CB67B058F266}c:\\program files\\vuze\\azureus.exe"= UDP:c:\program files\vuze\azureus.exe:Azureus
"UDP Query User{FE22003D-32DA-4AF2-AE58-C09CFD0628C0}c:\\program files\\vuze\\azureus.exe"= TCP:c:\program files\vuze\azureus.exe:Azureus
"{ECADC26E-9281-4861-BE99-1626CAA0FB7D}"= UDP:c:\program files\Adobe\Adobe Bridge CS4\Bridge.exe:Adobe Bridge CS4
"{D5711932-DD1D-4EE5-B87C-07E5608E47A0}"= TCP:c:\program files\Adobe\Adobe Bridge CS4\Bridge.exe:Adobe Bridge CS4
"{EF022531-98A0-47D7-87E8-0878496C6270}"= UDP:c:\games\World of Warcraft\Wow.exe:World of Warcraft
"{8BD8F904-D7B8-40E6-AAF7-185910146329}"= TCP:c:\games\World of Warcraft\Wow.exe:World of Warcraft
"TCP Query User{3A9C70BB-AADB-4CFD-8896-A8578D5D9A31}c:\\games\\steam\\steamapps\\coldpain_com\\team fortress 2\\hl2.exe"= UDP:c:\games\steam\steamapps\coldpain_com\team fortress 2\hl2.exe:hl2
"UDP Query User{4BA76B47-D443-4258-B0AA-E39A89EC5D6D}c:\\games\\steam\\steamapps\\coldpain_com\\team fortress 2\\hl2.exe"= TCP:c:\games\steam\steamapps\coldpain_com\team fortress 2\hl2.exe:hl2
"{5CACC4B7-3044-49C3-A208-00A82449665A}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{48572393-228F-4CFE-A4B0-962F495C0CD4}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{8A817F09-9C94-479A-A423-7AD50E246354}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{CD070C4C-B0A7-4EF5-9363-E76D3288EFF6}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{407663BB-497D-4EF0-8F69-A58CDD5F90B6}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{F38E449A-E469-4FAE-8E68-A42ADFE1CC1A}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{61FEE3D5-A489-4F71-B8A8-6AF7828ED92F}"= c:\program files\Skype\Phone\Skype.exe:Skype
"TCP Query User{3A5A9888-84D6-4C62-BA6E-573C9D8B08C6}c:\\games\\steam\\steamapps\\coldpain_com\\counter-strike source\\hl2.exe"= UDP:c:\games\steam\steamapps\coldpain_com\counter-strike source\hl2.exe:hl2
"UDP Query User{6A5A890C-108E-49C6-B3B9-A130B96A7DC1}c:\\games\\steam\\steamapps\\coldpain_com\\counter-strike source\\hl2.exe"= TCP:c:\games\steam\steamapps\coldpain_com\counter-strike source\hl2.exe:hl2
R1 gdwfpcd;G DATA WFP CD;c:\windows\System32\drivers\gdwfpcd32.sys [19.11.2008 17:40 40392]
R1 GRD;G Data Rootkit Detector Driver;c:\windows\System32\drivers\GRD.sys [20.11.2008 03:05 29128]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\System32\atiesrxx.exe [16.03.2009 22:27 180224]
R2 AVKProxy;G Data AntiVirus Proxy;c:\program files\Common Files\G DATA\AVKProxy\AVKProxy.exe [02.03.2009 13:09 1117768]
R2 AVKService;G Data Scheduler;c:\program files\G DATA\AntiVirus\AVK\AVKService.exe [02.03.2009 13:09 388168]
R2 AVKWCtl;G Data Dateisystem Wächter;c:\program files\G DATA\AntiVirus\AVK\AVKWCtl.exe [25.02.2009 02:32 1206096]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\System32\TUProgSt.exe [18.12.2008 18:49 604416]
R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\System32\drivers\CT20XUT.sys [19.02.2009 18:42 198168]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\System32\drivers\CTEXFIFX.sys [19.02.2009 18:43 1353240]
R3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\System32\drivers\CTHWIUT.sys [19.02.2009 18:43 73752]
R3 GDMnIcpt;GDMnIcpt;c:\windows\System32\drivers\MiniIcpt.sys [19.11.2008 17:40 50632]
R3 GDScan;G Data Scanner;c:\program files\Common Files\G DATA\GDScan\GDScan.exe [25.02.2009 02:47 298568]
R3 ha20x22k;Creative 20X2 HAL Driver;c:\windows\System32\drivers\ha20x22k.sys [19.02.2009 18:54 1222680]
R3 HookCentre;HookCentre;c:\windows\System32\drivers\HookCentre.sys [06.05.2009 13:14 32200]
S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [09.05.2009 19:59 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [02.04.2009 21:20 79360]
S3 Creative Media Toolbox 6 Licensing Service;Creative Media Toolbox 6 Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [02.04.2009 21:30 79360]
S3 CT20XUT;CT20XUT;c:\windows\System32\drivers\CT20XUT.sys [19.02.2009 18:42 198168]
S3 CTEXFIFX;CTEXFIFX;c:\windows\System32\drivers\CTEXFIFX.sys [19.02.2009 18:43 1353240]
S3 CTHWIUT;CTHWIUT;c:\windows\System32\drivers\CTHWIUT.sys [19.02.2009 18:43 73752]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [09.01.2009 14:10 55264]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [08.12.2008 18:01 533344]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [19.11.2008 17:13 33752]
--- Andere Dienste/Treiber im Speicher ---
*Deregistered* - sptd
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Inhalt des "geplante Tasks" Ordners
2009-05-25 c:\windows\Tasks\1-Klick-Wartung.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-03-20 14:17]
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
SafeBoot-procexp90.Sys
.
------- Zusätzlicher Suchlauf -------
.
uInternet Settings,ProxyOverride = *.local
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: Translate with &Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
FF - ProfilePath - c:\users\Pawel Wendt\AppData\Roaming\Mozilla\Firefox\Profiles\n06rtz2k.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
FF - component: c:\program files\Mozilla Firefox\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170633FE}\components\AvkWebFilterFF.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPiL77.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
---- FIREFOX Richtlinien ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-05-25 18:07
Windows 6.0.6001 Service Pack 1 NTFS
Scanne versteckte Prozesse...
Scanne versteckte Autostarteinträge...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTxfiHlp = CTXFIHLP.EXE?
Scanne versteckte Dateien...
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
[HKEY_USERS\S-1-5-21-2584977684-1754756360-1121880361-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:63,eb,d4,03,08,6f,2c,8a,49,7a,6a,37,90,d1,38,d7,f8,cb,cc,10,fa,70,db,
26,f7,0f,71,e1,8e,48,98,cf,fd,76,cf,6b,61,3c,6e,04,46,0e,71,95,49,3e,d6,7f,\
"??"=hex:6d,e4,9a,59,e8,8b,9e,9c,6e,45,cc,40,3e,e5,f9,d0
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:c8,28,51,af,b0,29,a3,98,b8,69,2b,c4,f2,
ea,eb,40,e2,63,26,f1,3f,c8,ff,68,19,8d,1d,ac,ac,ca,69,79,e2,63,26,f1,3f,c8,\
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:6a,9c,d6,61,af,45,84,18,dc,8a,6e,52,89,
fd,c3,d8,6a,9c,d6,61,af,45,84,18,0d,fa,0a,b0,15,0f,e7,68,6a,9c,d6,61,af,45,\
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:ff,7c,85,e0,43,d4,0e,fe,55,15,ea,28,8c,
73,d7,82,ff,7c,85,e0,43,d4,0e,fe,d1,9e,af,8b,b4,46,d2,03,ff,7c,85,e0,43,d4,\
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:3e,1e,9e,e0,57,5a,93,61,30,51,0d,46,c6,
5b,27,2e,86,8c,21,01,be,91,eb,e7,f5,b3,e4,8e,85,55,cc,ec,86,8c,21,01,be,91,\
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:cd,44,cd,b9,a6,33,6c,cd,5c,19,16,27,eb,
45,1c,5c,f5,1d,4d,73,a8,13,5c,05,4d,ba,69,53,f0,1c,ef,71,f5,1d,4d,73,a8,13,\
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:b0,18,ed,a7,3f,8d,37,a4,b6,45,e8,60,bf,
e9,b8,6e,df,20,58,62,78,6b,cf,c8,6b,17,c4,c0,c3,58,c1,8e,df,20,58,62,78,6b,\
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,2b,cf,93,b9,30,
7f,50,8e,fb,a7,78,e6,12,2f,9a,ea,de,9a,80,18,84,83,ef,6c,fb,a7,78,e6,12,2f,\
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:83,6c,56,8b,a0,85,96,ab,f8,af,a8,f6,ff,
7f,05,8e,01,3a,48,fc,e8,04,4a,f1,f6,88,1b,65,bb,da,8c,3d,01,3a,48,fc,e8,04,\
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:f6,0f,4e,58,98,5b,89,c9,f5,29,cf,70,9d,
be,48,c2,f6,0f,4e,58,98,5b,89,c9,87,68,52,de,36,fb,b3,f2,f6,0f,4e,58,98,5b,\
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:3d,ce,ea,26,2d,45,aa,78,c8,53,d4,78,d8,
72,c8,3d,3d,ce,ea,26,2d,45,aa,78,b9,d3,c0,43,56,e2,bb,43,3d,ce,ea,26,2d,45,\
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:2a,b7,cc,b5,b9,7f,41,e7,06,0d,54,5b,19,
44,35,7e,2a,b7,cc,b5,b9,7f,41,e7,34,bb,6a,78,4d,22,3f,73,2a,b7,cc,b5,b9,7f,\
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:6c,43,2d,1e,aa,22,2f,9c,9c,9b,85,f5,b4,
14,70,3f,6c,43,2d,1e,aa,22,2f,9c,c6,d4,4b,6b,dc,d3,f6,3d,6c,43,2d,1e,aa,22,\
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
- - - - - - - > 'Explorer.exe'(9884)
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\program files\Babylon\Babylon-Pro\Captlib.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\System32\audiodg.exe
c:\program files\Creative\Shared Files\CTAudSvc.exe
c:\windows\System32\WUDFHost.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\program files\Common Files\logishrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\windows\System32\atieclxx.exe
c:\program files\Common Files\logishrd\LVCOMSER\LVComSer.exe
c:\program files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
c:\program files\Logitech\GamePanel Software\LCD Manager\Applets\LCDCountdown.exe
c:\program files\Logitech\GamePanel Software\LCD Manager\Applets\LCDPop3.exe
c:\windows\System32\CTxfispi.exe
c:\program files\Logitech\GamePanel Software\LCD Manager\Applets\LCDMedia.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2009-05-25 18:10 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2009-05-25 16:10
ComboFix2.txt 2009-05-25 14:37
Vor Suchlauf: 15 Verzeichnis(se), 75.204.091.904 Bytes frei
Nach Suchlauf: 15 Verzeichnis(se), 74.949.128.192 Bytes frei
459 --- E O F --- 2009-05-22 13:30
Hochladen war erfolgreich