ComboFix 08-01-04.1 - himmelweiss 2008-01-06 7:39:50.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1031.18.2099 [GMT 1:00]
ausgeführt von:: C:\appz\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Weitere L”schungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Users\himmelweiss\AppData\Roaming\addon.dat
C:\Windows\regedit.com
C:\Windows\system32\drivers\srosa.sys
C:\Windows\system32\taskmgr.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_SROSA
-------\srosa
((((((((((((((((((((((( Dateien erstellt von 2007-12-06 bis 2008-01-06 ))))))))))))))))))))))))))))))
.
2008-01-06 07:29 . 2000-08-31 08:00 51,200 --a------ C:\Windows\NirCmd.exe
2008-01-06 07:17 . 2008-01-06 07:29 <DIR> d-------- C:\Program Files\EsetOnlineScanner
2008-01-06 06:00 . 2008-01-06 06:00 <DIR> d-------- C:\fsaua.data
2008-01-06 05:34 . 2008-01-06 05:34 2,048 --a------ C:\Windows\System32\tzres.dll
2008-01-06 05:20 . 2008-01-06 05:20 <DIR> d-------- C:\SD
2008-01-06 04:30 . 2008-01-06 06:51 <DIR> d-------- C:\kav
2008-01-06 04:29 . 2008-01-06 04:29 <DIR> d-a------ C:\Windows\zts2.exe
2008-01-06 04:29 . 2008-01-06 04:29 <DIR> d-a------ C:\Windows\System32\vcmgcd32.dll
2008-01-06 04:29 . 2008-01-06 04:29 <DIR> d-a------ C:\Windows\System32\iifgfgf.dll
2008-01-06 04:29 . 2008-01-06 04:29 <DIR> d-a------ C:\Windows\rundll16.exe
2008-01-06 04:29 . 2008-01-06 04:29 <DIR> d-a------ C:\Windows\rundl132.dll
2008-01-06 04:29 . 2008-01-06 04:29 <DIR> d-a------ C:\Windows\logo1_.exe
2008-01-06 04:28 . 2008-01-06 04:28 26 --a------ C:\Windows\Lic.xxx
2008-01-06 04:14 . 2008-01-06 04:14 <DIR> d-------- C:\Users\himmelweiss\.housecall6.6
2008-01-06 04:14 . 2008-01-06 04:14 102,664 --a------ C:\Windows\System32\drivers\tmcomm.sys
2008-01-06 03:55 . 2006-11-02 10:45 163,840 --a------ C:\Windows\System32\T.COM
2008-01-06 03:55 . 2006-11-02 10:45 134,656 --a------ C:\Windows\R.COM
2008-01-06 03:22 . 2008-01-06 03:22 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-06 03:08 . 2008-01-06 07:45 2,287,648 --ahs---- C:\Windows\System32\drivers\fidbox.dat
2008-01-06 03:08 . 2008-01-06 07:45 28,928 --ahs---- C:\Windows\System32\drivers\fidbox.idx
2008-01-06 02:32 . 2008-01-06 02:32 <DIR> d-------- C:\Windows\System32\Kaspersky Lab
2008-01-06 02:32 . 2008-01-06 06:49 <DIR> d-------- C:\Users\All Users\Kaspersky Lab
2008-01-06 02:32 . 2008-01-06 06:49 <DIR> d-------- C:\ProgramData\Kaspersky Lab
2008-01-05 20:29 . 2008-01-05 20:29 <DIR> d-------- C:\Users\All Users\InstallShield
2008-01-05 20:29 . 2008-01-05 20:29 <DIR> d-------- C:\ProgramData\InstallShield
2008-01-05 20:29 . 2004-06-16 06:03 73,728 --a------ C:\Windows\System32\ISUSPM.cpl
2008-01-05 20:28 . 2008-01-05 20:28 271,360 --a------ C:\Windows\System32\drivers\atksgt.sys
2008-01-05 20:27 . 2008-01-05 20:27 18,048 --a------ C:\Windows\System32\drivers\lirsgt.sys
2008-01-05 20:23 . 2008-01-05 20:28 <DIR> d-------- C:\Program Files\Gothic III
2008-01-04 19:53 . 2008-01-04 19:53 <DIR> d--h----- C:\Program Files\win32GI
2008-01-04 09:58 . 2004-03-26 02:09 495,252 --a------ C:\Windows\System32\drivers\blah
2008-01-04 09:55 . 2008-01-06 05:21 <DIR> d-------- C:\Windows\System32\drivers\down
2007-12-29 09:10 . 2008-01-06 06:41 54,156 --ah----- C:\Windows\QTFont.qfn
2007-12-29 09:10 . 2007-12-29 09:10 1,409 --a------ C:\Windows\QTFont.for
2007-12-29 09:09 . 2007-12-29 09:09 <DIR> d-------- C:\Program Files\QuickTime
2007-12-27 00:15 . 2007-12-27 00:15 3,492 --a------ C:\eve4.m3u
2007-12-27 00:11 . 2007-12-27 00:11 <DIR> d-------- C:\Program Files\Dragon UnPACKer 5
2007-12-25 07:26 . 2007-12-25 07:26 749,312 --a------ C:\NTCEveTycoonGuide003.pdf
2007-12-21 23:32 . 2007-12-21 23:32 465 --a------ C:\eve3.m3u
2007-12-20 16:22 . 2007-12-20 17:12 7,948 --a------ C:\eve2.m3u
2007-12-20 07:05 . 2007-12-20 07:19 1,351 --a------ C:\eve.m3u
2007-12-19 04:03 . 2007-12-21 21:43 <DIR> d-------- C:\Users\himmelweiss\AppData\Roaming\teamspeak2
2007-12-19 04:03 . 2007-12-19 04:03 <DIR> d-------- C:\Program Files\Teamspeak2_RC2
2007-12-19 04:03 . 2007-12-19 04:03 34,064 --a------ C:\Windows\System32\lhacm.acm
2007-12-18 15:45 . 2007-12-18 15:46 <DIR> d-------- C:\Users\himmelweiss\AppData\Roaming\EVEMon
2007-12-18 15:45 . 2007-12-18 15:45 <DIR> d-------- C:\Program Files\EVEMon
2007-12-18 00:04 . 2007-12-18 00:04 <DIR> d-------- C:\Program Files\DeepSilver
2007-12-11 21:35 . 2007-12-11 21:35 3,438,063 --a------ C:\Haladas_Bergbau_Anleitung_german_2_2.pdf
2007-12-11 10:57 . 2007-12-11 10:57 65,536 --a------ C:\Windows\System32\QuickTimeVR.qtx
2007-12-11 10:57 . 2007-12-11 10:57 49,152 --a------ C:\Windows\System32\QuickTime.qts
2007-12-10 18:23 . 2007-12-10 18:23 1,215,363 --a------ C:\sternschnuppe Kopie.jpg
2007-12-10 18:18 . 2007-12-10 18:23 7,482,754 --a------ C:\sternschnuppe.psd
2007-12-10 18:09 . 2007-12-10 18:09 6,502 --a------ C:\sternschnuppe-2.gif
2007-12-09 21:33 . 2007-07-19 18:14 3,727,720 --a------ C:\Windows\System32\d3dx9_35.dll
2007-12-09 21:21 . 2007-12-09 21:21 <DIR> d-------- C:\Program Files\CCP
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-06 15:46 3,471,032 ----a-w C:\Windows\System32\ntoskrnl.exe
2008-01-06 06:39 --------- d-----w C:\Users\himmelweiss\AppData\Roaming\OpenOffice.org2
2008-01-06 04:10 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2008-01-06 03:32 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-01-06 02:43 --------- d-----w C:\Program Files\Tablet
2008-01-06 02:36 --------- d-----w C:\Program Files\Skype
2008-01-06 02:36 --------- d-----w C:\Program Files\Bradbury
2008-01-06 02:21 --------- d-----w C:\Program Files\Google
2008-01-06 02:18 --------- d-----w C:\Users\himmelweiss\AppData\Roaming\IGN_DLM
2008-01-06 02:11 --------- d-----w C:\Program Files\Autodesk
2008-01-06 02:05 --------- d-----w C:\ProgramData\Autodesk
2008-01-06 02:05 --------- d-----w C:\Program Files\Common Files\Autodesk Shared
2008-01-06 01:02 --------- d-----w C:\Users\himmelweiss\AppData\Roaming\WTablet
2008-01-05 19:29 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-01-05 19:28 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-28 11:19 --------- d-----w C:\Users\himmelweiss\AppData\Roaming\MySQL
2007-12-11 00:02 --------- d-----w C:\ProgramData\NVIDIA
2007-11-26 14:44 --------- d-----w C:\Program Files\SmartFTP Client 2.0
2007-11-18 10:11 --------- d-----w C:\Program Files\Trillian
2007-11-17 18:50 1,244,672 ----a-w C:\Windows\System32\mcmde.dll
2007-11-15 14:08 --------- d-----w C:\Program Files\Apple Software Update
2007-11-15 01:42 --------- d-----w C:\Users\himmelweiss\AppData\Roaming\Ventrilo
2007-11-15 00:48 --------- d-----w C:\Program Files\Ventrilo
2007-11-14 02:03 704,000 ----a-w C:\Windows\System32\PhotoScreensaver.scr
2007-11-14 02:03 67,584 ----a-w C:\Windows\System32\wlanhlp.dll
2007-11-14 02:03 542,720 ----a-w C:\Windows\System32\sysmain.dll
2007-11-14 02:03 502,784 ----a-w C:\Windows\System32\wlansvc.dll
2007-11-14 02:03 47,104 ----a-w C:\Windows\System32\wlanapi.dll
2007-11-14 02:03 3,504,824 ----a-w C:\Windows\System32\ntkrnlpa.exe
2007-11-14 02:03 297,984 ----a-w C:\Windows\System32\wlansec.dll
2007-11-14 02:03 290,816 ----a-w C:\Windows\System32\wlanmsm.dll
2007-11-14 02:03 258,232 ----a-w C:\Windows\system32\drivers\acpi.sys
2007-11-14 02:03 24,064 ----a-w C:\Windows\System32\wtsapi32.dll
2007-11-14 02:03 2,923,520 ----a-w C:\Windows\explorer.exe
2007-11-14 02:03 2,027,008 ----a-w C:\Windows\System32\win32k.sys
2007-11-14 02:01 8,704 ----a-w C:\Windows\System32\hcrstco.dll
2007-11-14 02:01 8,704 ----a-w C:\Windows\System32\hccoin.dll
2007-11-14 02:01 73,216 ----a-w C:\Windows\system32\drivers\usbccgp.sys
2007-11-14 02:01 5,888 ----a-w C:\Windows\system32\drivers\usbd.sys
2007-11-14 02:01 38,400 ----a-w C:\Windows\system32\drivers\usbehci.sys
2007-11-14 02:01 224,768 ----a-w C:\Windows\system32\drivers\usbport.sys
2007-11-14 02:01 192,000 ----a-w C:\Windows\system32\drivers\usbhub.sys
2007-11-14 02:01 19,456 ----a-w C:\Windows\system32\drivers\usbohci.sys
2007-11-14 02:01 --------- d-----w C:\Program Files\Windows Mail
2007-11-12 00:24 --------- d-----w C:\Program Files\Common Files\Adobe
2007-11-09 12:24 --------- d-----w C:\Program Files\Movie Player
2007-10-09 18:23 8,147,968 ----a-w C:\Windows\System32\wmploc.DLL
2007-10-09 18:23 7,680 ----a-w C:\Windows\System32\spwmp.dll
2007-10-09 18:23 4,096 ----a-w C:\Windows\System32\dxmasf.dll
2007-10-09 18:23 356,864 ----a-w C:\Windows\System32\MediaMetadataHandler.dll
2007-10-09 18:22 56,320 ----a-w C:\Windows\System32\iesetup.dll
2007-10-09 18:22 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2007-10-09 18:22 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2007-10-09 18:21 84,480 ----a-w C:\Windows\System32\INETRES.dll
2007-10-09 18:21 788,992 ----a-w C:\Windows\System32\rpcrt4.dll
2007-10-09 18:21 737,792 ----a-w C:\Windows\System32\inetcomm.dll
2007-08-30 16:08 174 --sha-w C:\Program Files\desktop.ini
.
Code:
<pre>
------r 1,037,644 2002-02-18 11:41:40 C:\Poser Stuff\figures\Dragons Volume 1\DAZ3D_Storybook Dragon Poses .exe
</pre>
(((((((((((((((((((((((((((( Autostart Punkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Hinweis* leere Eintrage & legitime Standardeintrage werden nicht angezeigt.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\windows sidebar\sidebar.exe" [2006-11-02 13:35 1196032]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-11-12 11:48 157592]
"PCTV 310i Antenna Power"="C:\Program Files\Pinnacle\Shared Files\Drivers\Tools\PCTV 310i Antenna Power.exe" [2006-09-07 07:04 94208]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2004-03-26 02:09 495252]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 13:35 125440]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 13:36 201728]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-06-16 06:03 221184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40 155648]
"Dell AIO Printer A920"="C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe" [2007-03-28 11:10 275952]
"Easy-PrintToolBox"="C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.exe" [2004-01-14 02:10 409600]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-02-13 19:29 35328]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-06-22 17:07 180269]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-07-31 17:44 271672]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-10-04 17:14 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-10-04 17:14 8497696]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-10-04 17:14 81920]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56 286720]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 06:03 81920]
C:\Users\himmelweiss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 2.1.lnk - C:\Program Files\OpenOffice.org 2.1\program\quickstart.exe [2006-11-27 16:45:48]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 20:16:50]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 09:15:00]
Monitor Apache Servers.lnk - C:\Apache2.2\bin\ApacheMonitor.exe [2007-01-09 23:20:44]
Registrierungsprogramm ausfhren.lnk - C:\Program Files\WiFiConnector\NintendoWFCReg.exe [2007-10-21 18:32:28]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 relog_ap
R2 LicCtrlService;LicCtrl Service;C:\Windows\runservice.exe [2007-03-29 21:00]
R3 Ph3xIB32;Philips 713x Inbox PCI TV Card;C:\Windows\system32\DRIVERS\Ph3xIB32.sys [2007-04-03 09:43]
R3 RTSTOR;USB Mass Storage Device;C:\Windows\system32\drivers\RTSTOR.SYS [2007-05-11 19:09]
S3 3xHybrid;Pinnacle PCTV 100i-110i-300i-310i-MCE;C:\Windows\system32\DRIVERS\3xHybrid.sys [2006-11-22 07:53]
S3 HCWBT8xx;Hauppauge WinTV 848/9 WDM Video Driver;C:\Windows\system32\drivers\HCWBT8XX.sys [2006-01-25 16:14]
S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-01-18 19:03]
S3 tbhsd;Tunebite High-Speed Dubbing;C:\Windows\system32\drivers\tbhsd.sys [2006-12-14 16:54]
S3 u2kg54;BUFFALO WLI-U2-KG54 Wireless LAN Adapter Service;C:\Windows\system32\DRIVERS\rt2500usb.sys [2004-06-22 09:15]
S4 dlbk_device;dlbk_device;C:\Windows\system32\dlbkcoms.exe [2007-03-28 11:08]
S4 MySQL5;MySQL5;"C:\Program Files\MySQL\MySQL Server 5.1\bin\mysqld-nt" []
S4 viamraid;viamraid;C:\Windows\system32\drivers\viamraid.sys [2006-03-31 01:18]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalSystemNetworkRestricted REG_MULTI_SZ hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
C:\Windows\system32\unregmp2.exe /ShowWMP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI
.
Inhalt des "geplante Tasks" Ordners
"2008-01-05 07:52:07 C:\Windows\Tasks\User_Feed_Synchronization-{C588710E-122A-4644-8518-992713926BF7}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-06 07:49:13
Windows 6.0.6000 NTFS
Scanne versteckte Prozesse...
Scanne versteckte Autostart Eintr„ge...
Scanne versteckte Dateien...
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
**************************************************************************
.
Zeit der Fertigstellung: 2008-01-06 7:52:57 - machine was rebooted [himmelweiss]
ComboFix-quarantined-files.txt 2008-01-06 06:52:54
.
2008-01-06 04:48:30 --- E O F ---