Cf Log:
ComboFix 07-12-21.4 - Jens 2007-12-28 23:12:42.6 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1031.18.606 [GMT 1:00]
ausgeführt von:: F:\Dokumente und Einstellungen\Jens\Desktop\ComboFix.exe
Command switches used :: F:\Dokumente und Einstellungen\Jens\Desktop\CFScript.txt
* Neuer Wiederherstellungspunkt wurde erstellt
FILE
F:\WINDOWS\system32\drivers\4BE93C14-F537-47D5-BFA5-403A93771860.cxv
F:\WINDOWS\system32\drivers\532AA62E-4949-4503-A766-3A58A68F9937.cxv
F:\WINDOWS\system32\mcrh.tmp
F:\WINDOWS\system32\ndaTqsVqrX.dll
F:\WINDOWS\system32\RCX29.tmp
F:\WINDOWS\system32\RCX36.tmp
F:\WINDOWS\system32\RCX43.tmp
F:\WINDOWS\system32\yayawuv.dll
.
(((((((((((((((((((((((((((((((((((( Weitere L”schungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
F:\VundoFix Backups
F:\VundoFix Backups\geebx.dll.bad
F:\VundoFix Backups\jjkmp.ini.bad
F:\VundoFix Backups\jjkmp.ini2.bad
F:\VundoFix Backups\NeroCheck.exe.bad
F:\VundoFix Backups\nmllm.ini.bad
F:\VundoFix Backups\nmllm.ini2.bad
F:\VundoFix Backups\xbeeg.ini.bad
F:\VundoFix Backups\xbeeg.ini2.bad
F:\WINDOWS\system32\drivers\4BE93C14-F537-47D5-BFA5-403A93771860.cxv
F:\WINDOWS\system32\drivers\532AA62E-4949-4503-A766-3A58A68F9937.cxv
F:\WINDOWS\system32\mcrh.tmp
.
((((((((((((((((((((((( Dateien erstellt von 2007-11-28 bis 2007-12-28 ))))))))))))))))))))))))))))))
.
2007-12-28 20:42 . 2007-12-28 23:34 3,551,776 --ahs---- F:\WINDOWS\system32\drivers\fidbox.dat
2007-12-28 20:42 . 2007-12-28 23:16 50,708 --ahs---- F:\WINDOWS\system32\drivers\fidbox.idx
2007-12-28 20:42 . 2007-12-28 23:18 8,992 --ahs---- F:\WINDOWS\system32\drivers\fidbox2.dat
2007-12-28 20:42 . 2007-12-28 23:16 1,892 --ahs---- F:\WINDOWS\system32\drivers\fidbox2.idx
2007-12-28 20:26 . 2007-12-28 20:26 78,415 --a------ F:\WINDOWS\system32\drivers\klif.cab
2007-12-28 13:08 . 2007-12-28 13:08 <DIR> d-------- F:\MapSource
2007-12-28 13:00 . 2007-12-28 13:10 <DIR> d-------- F:\Garmin
2007-12-28 12:19 . 2007-12-28 12:19 <DIR> d-------- F:\Dokumente und Einstellungen\Jens\Anwendungsdaten\GARMIN
2007-12-28 11:16 . 2007-12-28 11:16 <DIR> d-------- F:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Google Updater
2007-12-28 02:06 . 2007-07-30 19:19 271,224 --a------ F:\WINDOWS\system32\mucltui.dll
2007-12-28 02:06 . 2007-07-30 19:18 30,072 --a------ F:\WINDOWS\system32\mucltui.dll.mui
2007-12-27 22:40 . 2007-12-28 20:29 <DIR> d-------- F:\Programme\Kaspersky Lab
2007-12-27 22:40 . 2007-12-28 20:49 91,492 --a------ F:\WINDOWS\system32\drivers\klin.dat
2007-12-27 22:40 . 2007-12-28 20:49 85,860 --a------ F:\WINDOWS\system32\drivers\klick.dat
2007-12-27 17:06 . 2007-12-27 17:57 <DIR> d-------- F:\Programme\UBCD4Win
2007-12-27 09:37 . 2007-12-27 09:37 <DIR> d-------- F:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Prevx
2007-12-27 09:36 . 2007-12-27 09:38 <DIR> d-------- F:\Dokumente und Einstellungen\Jens\Anwendungsdaten\PrevxCSI
2007-12-27 09:28 . 2007-12-27 18:04 7,646 --ahs---- F:\WINDOWS\system32\nmllm.ini2
2007-12-27 09:28 . 2007-12-27 18:05 7,646 --ahs---- F:\WINDOWS\system32\nmllm.ini
2007-12-25 20:37 . 2007-12-25 21:50 <DIR> d-------- F:\Programme\Windows Defender
2007-12-25 20:33 . 2007-12-26 08:13 <DIR> d-------- F:\Programme\SpywareGuard
2007-12-25 20:30 . 2007-12-25 20:32 <DIR> d-------- F:\Programme\SpywareBlaster
2007-12-25 20:30 . 2005-08-25 18:19 115,920 --a------ F:\WINDOWS\system32\MSINET.OCX
2007-12-24 17:03 . 2007-12-24 17:03 <DIR> d-------- F:\WINDOWS\system32\Kaspersky Lab
2007-12-24 17:03 . 2007-12-28 23:34 <DIR> d-------- F:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Kaspersky Lab
2007-12-24 16:06 . 2007-12-24 16:06 250 --a------ F:\WINDOWS\gmer.ini
2007-12-24 09:15 . 2007-12-24 09:21 <DIR> d-------- F:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Spybot - Search & Destroy
2007-12-24 02:42 . 2006-07-14 01:35 <DIR> d--h----- F:\Dokumente und Einstellungen\Administrator\Vorlagen
2007-12-24 02:42 . 2006-07-15 00:41 <DIR> dr------- F:\Dokumente und Einstellungen\Administrator\Startmen
2007-12-24 02:42 . 2006-07-15 00:41 <DIR> d--h----- F:\Dokumente und Einstellungen\Administrator\Netzwerkumgebung
2007-12-24 02:42 . 2007-12-27 09:24 <DIR> d--h----- F:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen
2007-12-24 02:42 . 2006-07-15 00:41 <DIR> d-------- F:\Dokumente und Einstellungen\Administrator\Favoriten
2007-12-24 02:42 . 2006-07-15 00:41 <DIR> d--h----- F:\Dokumente und Einstellungen\Administrator\Druckumgebung
2007-12-24 02:42 . 2006-07-15 00:41 <DIR> dr-h----- F:\Dokumente und Einstellungen\Administrator\Anwendungsdaten
2007-12-24 02:33 . 2007-12-24 02:33 <DIR> d-------- F:\Programme\Trend Micro
2007-12-23 15:55 . 2007-12-23 23:31 155,648 --a------ F:\WINDOWS\system32\NeroCheck .exe
2007-12-23 11:58 . 2007-12-23 11:59 <DIR> d-------- F:\Dokumente und Einstellungen\All Users\Anwendungsdaten\WinZip
2007-12-19 19:51 . 2007-12-19 19:51 114,496 --a------ F:\WINDOWS\system32\drivers\prodrv04.sys
2007-12-19 19:51 . 1999-06-23 17:13 86,016 --a------ F:\WINDOWS\unvise32.exe
2007-12-01 12:50 . 2007-12-01 12:50 <DIR> d-------- F:\Dokumente und Einstellungen\Jens\Anwendungsdaten\T-Online
2007-11-30 07:42 . 2007-11-30 07:42 <DIR> d-------- F:\Programme\Free Fire Screensaver
2007-11-30 07:42 . 2007-11-30 07:42 <DIR> d-------- F:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Laconic Software
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-28 12:10 --------- d-----w F:\Programme\GPS Software
2007-12-28 11:14 --------- d--h--w F:\Programme\InstallShield Installation Information
2007-12-28 11:14 --------- d-----w F:\Programme\Quicken2007
2007-12-28 11:13 --------- d-----w F:\Programme\Gemeinsame Dateien\Lexware
2007-12-28 10:16 --------- d-----w F:\Programme\Google
2007-12-28 01:09 --------- d-----w F:\Programme\iTunes
2007-12-27 15:46 --------- d-----w F:\Programme\Gemeinsame Dateien\Symantec Shared
2007-12-27 15:46 --------- d-----w F:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Symantec
2007-12-26 23:32 805 ----a-w F:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-12-26 23:32 10,740 ----a-w F:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-12-25 19:51 --------- d-----w F:\Programme\FreePDF_XP
2007-12-25 08:16 --------- d-----w F:\Programme\QuickTime
2007-12-24 15:07 --------- d-----w F:\Programme\Zinio
2007-12-24 01:28 --------- d-----w F:\Programme\Java
2007-12-20 17:04 --------- d-----w F:\Dokumente und Einstellungen\Jens\Anwendungsdaten\ContentGuard
2007-12-08 12:02 --------- d-----w F:\Programme\Free Metronome
2007-11-17 12:29 --------- d-----w F:\Programme\ModPlug
2007-11-13 10:25 20,480 ----a-w F:\WINDOWS\system32\drivers\secdrv.sys
2007-11-11 17:34 --------- d-----w F:\Programme\Obtiv
2007-11-10 16:18 --------- d-----w F:\Programme\iPod
2007-11-02 19:02 --------- d-----w F:\Dokumente und Einstellungen\Birgit\Anwendungsdaten\Symantec
2007-11-01 22:24 --------- d-----w F:\Dokumente und Einstellungen\Jens\Anwendungsdaten\Symantec
2007-11-01 22:22 --------- d-----w F:\Programme\Windows Sidebar
2004-03-11 11:27 40,960 ----a-w F:\Programme\Uninstall_CDS.exe
.
((((((((((((((((((((((((((((( snapshot@2007-12-24_16.21.09.57 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-05-16 19:38:04 3,638 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\ARPPRODUCTICON.exe
+ 2007-12-28 09:21:58 3,638 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\ARPPRODUCTICON.exe
- 2007-05-16 19:38:04 761,856 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\NewShortcut1_65F9131C16CB40F6BE401B42772C2B44.exe
+ 2007-12-28 09:21:59 761,856 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\NewShortcut1_65F9131C16CB40F6BE401B42772C2B44.exe
- 2007-05-16 19:38:04 761,856 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\NewShortcut10_65F9131C16CB40F6BE401B42772C2B44.exe
+ 2007-12-28 09:21:58 761,856 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\NewShortcut10_65F9131C16CB40F6BE401B42772C2B44.exe
- 2007-05-16 19:38:04 40,960 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\NewShortcut12_65F9131C16CB40F6BE401B42772C2B44.EXE
+ 2007-12-28 09:21:58 40,960 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\NewShortcut12_65F9131C16CB40F6BE401B42772C2B44.EXE
- 2007-05-16 19:38:04 45,056 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\NewShortcut3_65F9131C16CB40F6BE401B42772C2B44.exe
+ 2007-12-28 09:21:58 45,056 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\NewShortcut3_65F9131C16CB40F6BE401B42772C2B44.exe
- 2007-05-16 19:38:04 45,056 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\NewShortcut4_65F9131C16CB40F6BE401B42772C2B44.exe
+ 2007-12-28 09:21:59 45,056 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\NewShortcut4_65F9131C16CB40F6BE401B42772C2B44.exe
- 2007-05-16 19:38:04 761,856 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\NewShortcut8_65F9131C16CB40F6BE401B42772C2B44.exe
+ 2007-12-28 09:21:58 761,856 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\NewShortcut8_65F9131C16CB40F6BE401B42772C2B44.exe
- 2007-05-16 19:38:04 761,856 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\NewShortcut9_65F9131C16CB40F6BE401B42772C2B44.exe
+ 2007-12-28 09:21:58 761,856 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\NewShortcut9_65F9131C16CB40F6BE401B42772C2B44.exe
- 2007-05-16 19:38:04 93,184 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\OpinionDlx_15411A8C34CC41BBA48C52E3C052F20F.exe
+ 2007-12-28 09:21:58 93,184 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\OpinionDlx_15411A8C34CC41BBA48C52E3C052F20F.exe
- 2007-05-16 19:38:04 65,536 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\OpinionHBiz_15411A8C34CC41BBA48C52E3C052F20F.exe
+ 2007-12-28 09:21:58 65,536 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\OpinionHBiz_15411A8C34CC41BBA48C52E3C052F20F.exe
- 2007-05-16 19:38:04 93,184 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\OpinionReg_15411A8C34CC41BBA48C52E3C052F20F.exe
+ 2007-12-28 09:21:58 93,184 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\OpinionReg_15411A8C34CC41BBA48C52E3C052F20F.exe
- 2007-05-16 19:38:04 761,856 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\QuickenDlx2_65F9131C16CB40F6BE401B42772C2B44.exe
+ 2007-12-28 09:21:59 761,856 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\QuickenDlx2_65F9131C16CB40F6BE401B42772C2B44.exe
- 2007-05-16 19:38:04 761,856 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\QuickenDlx2_65F9131C16CB40F6BE401B42772C2B44_1.exe
+ 2007-12-28 09:21:59 761,856 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\QuickenDlx2_65F9131C16CB40F6BE401B42772C2B44_1.exe
- 2007-05-16 19:38:04 93,184 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\QuickenDlxUrl_15411A8C34CC41BBA48C52E3C052F20F.exe
+ 2007-12-28 09:21:58 93,184 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\QuickenDlxUrl_15411A8C34CC41BBA48C52E3C052F20F.exe
- 2007-05-16 19:38:04 65,536 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\QuickenHBizUrl_15411A8C34CC41BBA48C52E3C052F20F.exe
+ 2007-12-28 09:21:58 65,536 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\QuickenHBizUrl_15411A8C34CC41BBA48C52E3C052F20F.exe
- 2007-05-16 19:38:04 93,184 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\QuickenRegUrl_15411A8C34CC41BBA48C52E3C052F20F.exe
+ 2007-12-28 09:21:59 93,184 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\QuickenRegUrl_15411A8C34CC41BBA48C52E3C052F20F.exe
- 2007-05-16 19:38:04 45,056 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\QuickEntryDeskDlx1_65F9131C16CB40F6BE401B42772C2B44.exe
+ 2007-12-28 09:21:58 45,056 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\QuickEntryDeskDlx1_65F9131C16CB40F6BE401B42772C2B44.exe
- 2007-05-16 19:38:04 45,056 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\QuickEntryDeskHBiz1_65F9131C16CB40F6BE401B42772C2B44.exe
+ 2007-12-28 09:21:58 45,056 ----a-r F:\WINDOWS\Installer\{15411A8C-34CC-41BB-A48C-52E3C052F20F}\QuickEntryDeskHBiz1_65F9131C16CB40F6BE401B42772C2B44.exe
- 2007-11-10 16:18:50 102,400 ----a-r F:\WINDOWS\Installer\{E3FEE4E7-4488-4A3F-A6BD-13745936EADB}\iTunesIco.exe
+ 2007-12-28 01:09:18 102,400 ----a-r F:\WINDOWS\Installer\{E3FEE4E7-4488-4A3F-A6BD-13745936EADB}\iTunesIco.exe
- 2006-07-14 01:03:03 16,384 ----a-w F:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2007-12-28 19:42:49 32,768 ----a-w F:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2006-07-14 01:03:03 32,768 ----a-w F:\WINDOWS\system32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat
+ 2007-12-28 19:42:49 32,768 ----a-w F:\WINDOWS\system32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat
- 2006-07-14 01:03:03 32,768 ----a-w F:\WINDOWS\system32\config\systemprofile\Lokale Einstellungen\Verlauf\History.IE5\index.dat
+ 2007-12-28 19:42:49 32,768 ----a-w F:\WINDOWS\system32\config\systemprofile\Lokale Einstellungen\Verlauf\History.IE5\index.dat
- 2003-09-23 14:42:34 17,024 ----a-w F:\WINDOWS\system32\drivers\grmngen.sys
+ 2007-03-08 15:18:00 18,432 ----a-w F:\WINDOWS\system32\drivers\grmngen.sys
- 2003-09-23 14:42:34 7,296 ----a-w F:\WINDOWS\system32\drivers\grmnusb.sys
+ 2007-03-08 15:18:00 8,320 ----a-w F:\WINDOWS\system32\drivers\grmnusb.sys
+ 2007-04-28 15:51:02 110,360 ----a-w F:\WINDOWS\system32\drivers\kl1.sys
+ 2007-12-28 19:49:42 194,320 ----a-w F:\WINDOWS\system32\drivers\klif.sys
+ 2007-04-04 13:58:26 24,344 ----a-w F:\WINDOWS\system32\drivers\klim5.sys
- 2000-08-04 12:25:30 49,152 ----a-w F:\WINDOWS\system32\INETWH32.dll
+ 2000-08-04 14:25:30 49,152 ----a-w F:\WINDOWS\system32\INETWH32.dll
+ 2005-05-24 11:27:16 213,048 ----a-w F:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-10-21 20:40:14 94,208 ----a-w F:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-10-21 20:40:16 950,272 ----a-w F:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
+ 2007-06-28 11:51:48 206,088 ----a-w F:\WINDOWS\system32\klogon.dll
- 2003-03-18 19:20:00 1,060,864 ----a-w F:\WINDOWS\system32\mfc71.dll
+ 2007-03-21 19:39:00 1,060,864 ----a-w F:\WINDOWS\system32\MFC71.DLL
- 2003-03-18 18:14:52 499,712 ----a-w F:\WINDOWS\system32\msvcp71.dll
+ 2007-03-21 19:33:00 503,808 ----a-w F:\WINDOWS\system32\MSVCP71.DLL
- 2003-02-21 02:42:22 348,160 ----a-w F:\WINDOWS\system32\msvcr71.dll
+ 2007-03-21 19:33:00 348,160 ----a-w F:\WINDOWS\system32\MSVCR71.DLL
+ 2007-07-30 18:18:34 207,736 ----a-w F:\WINDOWS\system32\muweb.dll
- 2002-09-20 21:33:28 1,089,536 ----a-w F:\WINDOWS\system32\ROBOEX32.DLL
+ 2002-09-20 23:33:28 1,089,536 ----a-w F:\WINDOWS\system32\ROBOEX32.DLL
.
-- Snapshot reset to current date --
.
(((((((((((((((((((((((((((( Autostart Punkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Hinweis* leere Eintrage & legitime Standardeintrage werden nicht angezeigt.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
F:\PROGRA~1\GEMEIN~1\SYMANT~1\IDS\IPSBHO.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="F:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00]
"H/PC Connection Agent"="F:\Programme\Microsoft ActiveSync\wcescomm.exe" []
"Zinio DLM"="F:\Programme\Zinio\ZinioDeliveryManager.exe" []
"Polar Sync"="" []
"gStart"="F:\MapSource\gStart.exe" [2007-08-23 05:58]
"UninstallAbility"="F:\Programme\UninstallAbility\uability .exe" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="F:\WINDOWS\system32\NeroCheck.exe" []
"RemoteControl"="F:\Programme\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" []
"iTunesHelper"="F:\Programme\iTunes\iTunesHelper.exe" [2007-11-02 18:36]
"LexwareInfoService"="F:\Programme\Gemeinsame Dateien\Lexware\Update Manager\LxUpdateManager.exe" [2007-01-30 14:53]
"Windows Defender"="F:\Programme\Windows Defender\MSASCui.exe" []
"AVP"="F:\Programme\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [2007-06-28 12:51]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="F:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 13:00]
"DWQueuedReporting"="F:\PROGRA~1\GEMEIN~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 16:38]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=F:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS SmartDoctor]
F:\Programme\ASUS\SmartDoctor\SmartDoctor.exe /start
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Launch Ai Booster]
2005-06-16 14:36 3627520 --a------ F:\Programme\ASUS\Ai Booster\OverClk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
F:\Programme\Messenger\msmsgs.exe /background
R1 prodrv04;Star Force copy protection driver v4;F:\WINDOWS\system32\drivers\prodrv04.sys [2007-12-19 19:51]
R2 PLCNDIS5;PLCNDIS5 NDIS Protocol Driver;F:\WINDOWS\system32\plcndis5.sys [2004-05-17 10:21]
R3 cjusb;REINER SCT cyberJack pinpad/e-com USB;F:\WINDOWS\system32\DRIVERS\cjusb.sys [2005-10-04 07:24]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;F:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 14:58]
R3 TDslMgrService;DSL-Manager;"F:\Programme\DSL-Manager\DslMgrSvc.exe" [2007-08-01 14:36]
R3 TSMPacket;DSL-Manager Service;F:\WINDOWS\system32\DRIVERS\tsmpkt.sys [2007-06-26 11:53]
S2 Automatisches LiveUpdate - Scheduler;Automatisches LiveUpdate - Scheduler;"F:\Programme\Symantec\LiveUpdate\ALUSchedulerSvc.exe" []
S3 atidgllk;atidgllk;C:\Program Files\ASUS\SmartDoctor\atidgllk.sys []
S3 HotSpotFSvc;Hotspot Manager;"F:\Programme\Gemeinsame Dateien\T-COM\HotspotMgr\HotSpotFSvc.exe" []
.
Inhalt des "geplante Tasks" Ordners
"2007-12-24 07:21:35 F:\WINDOWS\Tasks\AntiSpyware Scheduled Scan.job"
- F:\Programme\AntiSpywareApp\AntiSpyware .ex
- F:\Programme\AntiSpywareApp
"2007-10-03 18:44:01 F:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- F:\Programme\Apple Software Update\SoftwareUpdate.exe
"2007-12-28 22:21:25 F:\WINDOWS\Tasks\MP Scheduled Scan.job"
- F:\Programme\Windows Defender\MpCmdRun.exe
"2007-12-24 19:00:03 F:\WINDOWS\Tasks\Norton Internet Security - Systemprüfung ausführen - Jens.job"
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-28 23:34:36
Windows 5.1.2600 Service Pack 2 NTFS
Scanne versteckte Prozesse...
Scanne versteckte Autostart Eintr„ge...
Scanne versteckte Dateien...
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
**************************************************************************
.
Zeit der Fertigstellung: 2007-12-28 23:35:42 - machine was rebooted
.
2007-12-12 14:24:37 --- E O F ---