New Combofix Log
ComboFix 08-04-16.5 - oWn4g3 2008-04-19 23:35:08.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1031.18.1523 [GMT 2:00]
ausgeführt von:: C:\Dokumente und Einstellungen\oWn4g3\Desktop\ComboFix.exe
Command switches used :: C:\Dokumente und Einstellungen\oWn4g3\Desktop\CFScript.txt
* Neuer Wiederherstellungspunkt wurde erstellt
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((( Dateien erstellt von 2008-03-19 bis 2008-04-19 ))))))))))))))))))))))))))))))
.
2008-04-17 22:50 . 2008-04-18 10:10 <DIR> d-------- C:\Programme\Hamachi
2008-04-17 19:15 . 2008-04-17 19:15 <DIR> d-------- C:\Programme\Pivot Stickfigure Animator
2008-04-16 14:45 . 2008-04-19 23:03 <DIR> d-------- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TrackMania
2008-04-16 10:15 . 2008-04-16 10:15 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-04-16 10:15 . 2008-04-16 10:15 <DIR> d-------- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Kaspersky Lab
2008-04-16 09:56 . 2008-04-16 09:56 <DIR> d-------- C:\Programme\Trend Micro
2008-04-16 09:26 . 2008-04-17 09:26 414 ---hs---- C:\WINDOWS\system32\tpjaohmc.ini
2008-04-15 16:30 . 2008-04-15 16:30 <DIR> d-------- C:\WINDOWS\nview
2008-04-15 16:30 . 2008-04-15 16:30 <DIR> d-------- C:\WINDOWS\nvidia icons
2008-04-15 16:30 . 2008-03-24 11:27 442,368 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2008-04-15 16:30 . 2008-03-24 19:52 442,368 --a------ C:\WINDOWS\system32\nvudisp.exe
2008-04-15 16:30 . 2008-04-19 22:57 175,605 --a------ C:\WINDOWS\system32\nvapps.xml
2008-04-15 16:30 . 2008-03-24 19:52 17,937 --a------ C:\WINDOWS\system32\nvdisp.nvu
2008-04-15 16:29 . 2008-04-15 16:29 <DIR> d-------- C:\NVIDIA
2008-04-15 14:56 . 2008-04-15 21:09 594 ---hs---- C:\WINDOWS\system32\hsaodgyr.ini
2008-04-15 14:47 . 2008-04-15 14:47 272,384 --------- C:\WINDOWS\system32\urqOHWPG.dll_old
2008-04-14 19:48 . 2008-04-15 14:42 <DIR> d-------- C:\Programme\tempa
2008-04-14 19:48 . 2008-04-08 11:50 206,191 --a------ C:\WINDOWS\system32\ati2sgav.exe
2008-04-14 16:07 . 2008-04-15 20:37 559 --a------ C:\WINDOWS\wininit.ini
2008-04-14 16:03 . 2008-04-14 16:03 307,968 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
2008-04-14 16:02 . 2008-02-27 13:15 28,416 --a------ C:\WINDOWS\system32\uxtuneup.dll
2008-04-14 07:20 . 2008-04-14 16:26 354 ---hs---- C:\WINDOWS\system32\tflvpiln.ini
2008-04-14 07:12 . 2008-04-17 08:54 101,091 --a------ C:\WINDOWS\BM1f718f8f.xml
2008-04-13 14:15 . 2008-04-13 14:16 <DIR> d-------- C:\WINDOWS\Sins Bonuspack
2008-04-11 21:36 . 2008-04-13 14:49 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-11 21:36 . 2008-04-11 21:36 1,409 --a------ C:\WINDOWS\QTFont.for
2008-04-11 17:07 . 2008-04-11 17:07 <DIR> d-------- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Ubisoft
2008-04-11 16:54 . 2008-04-14 19:48 441,652 --a------ C:\WINDOWS\system32\winamp.exe
2008-04-09 14:33 . 2008-04-09 14:33 <DIR> d-------- C:\WINDOWS\.jagex_cache_32
2008-04-06 12:39 . 2000-07-08 15:06 87,040 --a------ C:\WINDOWS\UnGins.exe
2008-04-06 12:34 . 2008-04-06 12:34 457,728 --a------ C:\xdfe52.dll
2008-04-06 12:34 . 2008-04-06 12:34 69,120 --a------ C:\atm.dll
2008-04-06 12:34 . 2008-04-06 12:34 45,056 --a------ C:\UNACE.dll
2008-04-03 01:26 . 2008-04-03 01:26 41,296 --a------ C:\WINDOWS\system32\xfcodec.dll
2008-03-27 17:17 . 2008-03-27 21:21 <DIR> d-------- C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Command & Conquer 3 Kanes Rache
2008-03-27 00:04 . 2008-04-05 01:41 <DIR> d---s---- C:\Programme\HLSW
2008-03-27 00:04 . 2008-04-05 02:52 <DIR> d-------- C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\HLSW
2008-03-26 18:26 . 2008-03-26 18:26 <DIR> d-------- C:\Programme\OpenOffice.org 2.4
2008-03-25 15:38 . 2008-03-25 15:38 34,198 --a------ C:\Star Wars Battlefront II .mds
2008-03-24 16:25 . 2008-03-25 15:42 3,914,283,008 --a------ C:\Star Wars Battlefront II .mdf
2008-03-23 18:05 . 2008-03-23 18:05 122 --a------ C:\WINDOWS\WA.INI
2008-03-23 18:04 . 2008-03-23 18:04 1,559,605 --a------ C:\WINDOWS\WANEUninstaller.exe
2008-03-23 15:36 . 2008-03-23 15:36 <DIR> d-------- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Age of Empires 3
2008-03-20 18:06 . 2008-03-20 18:06 <DIR> d-------- C:\WINDOWS\PreviewSoft
2008-03-20 18:06 . 2008-03-20 18:06 <DIR> d-------- C:\WINDOWS\Noslip
2008-03-20 18:06 . 2008-03-20 18:06 <DIR> d-------- C:\Programme\Ulead GIF Animator 5
2008-03-20 18:06 . 1999-10-15 13:50 1,056,768 --a------ C:\WINDOWS\system32\ROBOEX32.DLL
2008-03-20 18:06 . 1999-01-28 16:44 49,152 --a------ C:\WINDOWS\system32\INETWH32.dll
2008-03-20 18:06 . 2008-03-20 18:06 4,808 --a------ C:\WINDOWS\system32\gaeffect.sti
2008-03-20 18:06 . 2008-03-20 18:06 3,176 --a------ C:\WINDOWS\system32\gafilter.sti
2008-03-20 18:06 . 2008-03-20 20:50 550 --ah----- C:\os466477.bin
2008-03-20 18:06 . 2008-03-20 20:50 449 --ah----- C:\WINDOWS\system32\ws344069.ocx
2008-03-20 18:06 . 2008-03-20 20:50 312 --a------ C:\WINDOWS\ULEAD32.INI
2008-03-19 16:18 . 2008-03-19 16:18 <DIR> d-------- C:\Programme\Latein-Wörterbuch
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-19 16:01 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Xfire
2008-04-19 14:44 --------- d-----w C:\Programme\BOINC
2008-04-19 14:10 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\teamspeak2
2008-04-19 10:44 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\OpenOffice.org2
2008-04-19 10:18 --------- d-----w C:\Programme\Mozilla Thunderbird
2008-04-19 09:31 --------- d-s---w C:\Programme\Xfire
2008-04-18 14:14 --------- d-----w C:\Programme\PowerArchiver
2008-04-17 22:41 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Hamachi
2008-04-17 20:52 16,224 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys
2008-04-17 17:17 --------- d-----w C:\Programme\Trillian
2008-04-17 07:42 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-04-16 12:55 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Skype
2008-04-16 11:08 --------- d-----w C:\Programme\Gemeinsame Dateien\Wise Installation Wizard
2008-04-16 08:13 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\uTorrent
2008-04-15 19:27 --------- d-----w C:\Programme\mIRC
2008-04-15 19:27 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\mIRC
2008-04-15 17:11 --------- d-----w C:\Programme\Gemeinsame Dateien\Nero
2008-04-14 14:03 --------- d-----w C:\Programme\TuneUp Utilities 2008
2008-04-13 12:07 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Free Download Manager
2008-04-11 15:07 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-04-11 15:07 22,328 ----a-w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\PnkBstrK.sys
2008-04-11 15:06 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-04-11 15:03 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
2008-04-11 15:03 2,337,865 ----a-w C:\WINDOWS\system32\pbsvc.exe
2008-04-11 14:55 --------- d--h--w C:\Programme\InstallShield Installation Information
2008-04-10 16:10 --------- d-----w C:\Programme\SpeedFan
2008-03-31 16:16 --------- d-----w C:\Programme\Winamp
2008-03-31 16:16 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Winamp
2008-03-17 16:35 --------- d-----w C:\Programme\Java
2008-03-16 12:50 --------- d-----w C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Creative
2008-03-16 12:41 413,696 ----a-w C:\WINDOWS\system32\wrap_oal.dll
2008-03-16 12:41 110,592 ----a-w C:\WINDOWS\system32\OpenAL32.dll
2008-03-16 12:40 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Creative
2008-03-14 09:38 --------- d-----w C:\Programme\Audacity
2008-03-09 19:02 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\Media Player Classic
2008-03-09 19:01 --------- d-----w C:\Programme\XP Codec Pack
2008-03-07 13:24 97,216 ----a-w C:\WINDOWS\system32\drivers\AnyDVD.sys
2008-03-06 15:29 962,560 ----a-w C:\WINDOWS\system32\VSFilter.dll
2008-03-04 17:12 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
2008-03-02 19:27 --------- d---a-w C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP
2008-03-02 10:12 --------- d-----w C:\Dokumente und Einstellungen\oWn4g3\Anwendungsdaten\dvdcss
2008-02-29 09:21 --------- d-----w C:\Programme\AGEIA Technologies
2008-02-25 19:32 --------- d-----w C:\Programme\DivX
2008-02-25 08:45 189,464 ----a-w C:\WINDOWS\system32\drivers\haP17v2k.sys
2008-02-25 08:45 15,896 ----a-w C:\WINDOWS\system32\drivers\pfmodnt.sys
2008-02-25 08:44 92,696 ----a-w C:\WINDOWS\system32\drivers\emupia2k.sys
2008-02-25 08:44 797,720 ----a-w C:\WINDOWS\system32\drivers\ha10kx2k.sys
2008-02-25 08:44 162,840 ----a-w C:\WINDOWS\system32\drivers\haP16v2k.sys
2008-02-25 08:44 157,208 ----a-w C:\WINDOWS\system32\drivers\ctsfm2k.sys
2008-02-25 08:44 14,360 ----a-w C:\WINDOWS\system32\drivers\ctprxy2k.sys
2008-02-25 08:44 1,172,504 ----a-w C:\WINDOWS\system32\drivers\ha20x2k.sys
2008-02-25 08:43 524,312 ----a-w C:\WINDOWS\system32\drivers\ctaud2k.sys
2008-02-25 08:43 511,000 ----a-w C:\WINDOWS\system32\drivers\ctac32k.sys
2008-02-25 08:43 346,856 ----a-w C:\WINDOWS\system32\drivers\ctdvda2k.sys
2008-02-25 08:43 18,840 ----a-w C:\WINDOWS\system32\drivers\CTGAME.SYS
2008-02-25 08:43 127,000 ----a-w C:\WINDOWS\system32\drivers\ctoss2k.sys
2008-02-25 08:43 1,372,568 ----a-w C:\WINDOWS\system32\drivers\CTMMFILT.SYS
2008-02-25 08:43 1,366,424 ----a-w C:\WINDOWS\system32\drivers\CT0531FL.SYS
2008-02-25 08:41 72,728 ----a-w C:\WINDOWS\system32\CTHWIUT.DLL
2008-02-25 08:41 566,296 ----a-w C:\WINDOWS\system32\CTSBLFX.DLL
2008-02-25 08:41 329,240 ----a-w C:\WINDOWS\system32\CTEDSPSY.DLL
2008-02-25 08:41 286,232 ----a-w C:\WINDOWS\system32\CTEDSPFX.DLL
2008-02-25 08:41 174,104 ----a-w C:\WINDOWS\system32\CTEAPSFX.DLL
2008-02-25 08:41 170,520 ----a-w C:\WINDOWS\system32\CT20XUT.DLL
2008-02-25 08:41 134,680 ----a-w C:\WINDOWS\system32\CTEDSPIO.DLL
2008-02-25 08:41 100,888 ----a-w C:\WINDOWS\system32\CTERFXFX.DLL
2008-02-25 08:41 1,323,544 ----a-w C:\WINDOWS\system32\CTEXFIFX.DLL
2008-02-25 08:40 98,328 ----a-w C:\WINDOWS\system32\COMMONFX.DLL
2008-02-25 08:40 551,960 ----a-w C:\WINDOWS\system32\CTAUDFX.DLL
2008-02-21 02:05 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-02-21 02:05 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-02-21 02:05 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-02-21 02:05 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-02-21 02:04 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-02-21 02:04 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2008-02-21 02:04 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-02-21 02:04 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2008-02-21 02:04 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
2008-02-21 02:04 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-02-21 02:04 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2008-02-21 02:04 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-02-21 02:04 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2008-02-21 02:04 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2008-02-21 02:04 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2008-02-21 02:04 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2008-02-21 02:03 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-02-21 02:03 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-02-20 20:00 43,520 ----a-w C:\WINDOWS\system32\CTBurst.dll
2008-02-20 19:59 86,016 ----a-w C:\WINDOWS\system32\ctcoinst.dll
2008-02-20 19:59 34,816 ----a-w C:\WINDOWS\system32\a3d.dll
2008-02-20 19:59 27,648 ----a-w C:\WINDOWS\system32\ac3api.dll
2008-02-20 19:59 163,840 ----a-w C:\WINDOWS\system32\ctdvinst.dll
2008-02-20 19:55 969,216 ----a-w C:\WINDOWS\system32\CTxfispi.exe
2008-02-20 19:55 43,520 ----a-w C:\WINDOWS\system32\Ctxfireg.exe
2008-02-20 19:55 10,752 ----a-w C:\WINDOWS\system32\Ct20xspi.dll
2008-02-20 19:49 110,080 ----a-w C:\WINDOWS\system32\ctemupia.dll
2008-02-20 19:47 49,152 ----a-w C:\WINDOWS\system32\ctdproxy.dll
2008-02-20 19:47 46,592 ----a-w C:\WINDOWS\system32\ctasio.dll
2008-02-20 19:47 174,592 ----a-w C:\WINDOWS\system32\ct_oal.dll
2008-02-20 19:47 17,920 ----a-w C:\WINDOWS\system32\ctedasio.dll
.
((((((((((((((((((((((((((((( snapshot@2008-04-18_10.38.32.46 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-18 08:34:41 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-19 20:57:27 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2008-03-30 09:24:10 70,778 ----a-w C:\WINDOWS\system32\perfc007.dat
+ 2008-04-18 08:39:15 70,778 ----a-w C:\WINDOWS\system32\perfc007.dat
- 2008-03-30 09:24:10 58,732 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-04-18 08:39:15 58,732 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-03-30 09:24:10 405,448 ----a-w C:\WINDOWS\system32\perfh007.dat
+ 2008-04-18 08:39:15 405,448 ----a-w C:\WINDOWS\system32\perfh007.dat
- 2008-03-30 09:24:10 392,432 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-04-18 08:39:15 392,432 ----a-w C:\WINDOWS\system32\perfh009.dat
.
(((((((((((((((((((((((((((( Autostart Punkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Hinweis* leere Eintrage & legitime Standardeintrage werden nicht angezeigt.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BA7CB974-956C-456A-BB82-BEEC3B5E1750}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Pro Agent"="C:\Programme\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 15:08 136136]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:57 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Programme\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"Launch LCDMon"="C:\Programme\Gemeinsame Dateien\Logitech\LCD Manager\lcdmon.exe" [2007-04-26 17:54 774168]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 16:32 56080 C:\WINDOWS\KHALMNPR.Exe]
"VolPanel"="C:\Programme\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" [2006-07-13 15:11 122880]
"AudioDrvEmulator"="C:\Programme\Creative\Shared Files\Module Loader\DLLML.exe" [2005-11-04 19:07 49152]
"egui"="C:\Programme\ESET\ESET Smart Security\egui.exe" [2007-12-21 09:21 1443072]
"CTHelper"="CTHELPER.EXE" [2008-02-20 21:58 19456 C:\WINDOWS\system32\CtHelper.exe]
"ati2sgav"="C:\WINDOWS\system32\ati2sgav.exe" [2008-04-08 11:50 206191]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-03-24 19:52 13524992]
"nwiz"="nwiz.exe" [2008-03-24 19:52 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-03-24 19:52 86016]
"BM1f718f8f"="C:\WINDOWS\system32\iaecjrpf.dll" [ ]
C:\Dokumente und Einstellungen\All Users\Startmen\Programme\Autostart\
Logitech SetPoint.lnk - C:\Programme\Logitech\SetPoint\SetPoint.exe [2007-10-28 20:01:39 692224]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcBrRLf]
efcBrRLf.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
--a------ 2008-03-07 15:26 89024 C:\Programme\SlySoft\AnyDVD\AnyDVD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeviceDiscovery]
--a------ 2003-05-21 19:37 229437 C:\Programme\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2003-06-25 12:24 49152 C:\Programme\Hewlett-Packard\HP Software Update\HPWuSchd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
--a------ 2003-06-26 14:17 188416 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
--a------ 2007-05-11 02:08 2512392 C:\WINDOWS\system32\oodtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wscsvc"=2 (0x2)
"LxrSII1s"=2 (0x2)
"wuauserv"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"AlcoholAutomount"="C:\Programme\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="C:\Programme\QuickTime\qttask.exe" -atboottime
"UpdReg"=C:\WINDOWS\UpdReg.EXE
"Adobe Reader Speed Launcher"="C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"CTxfiHlp"=CTXFIHLP.EXE
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programme\\Bonjour\\mDNSResponder.exe"=
"C:\\Programme\\uTorrent\\uTorrent.exe"=
"D:\\Pro Evolution Soccer 2008\\PES2008.exe"=
"C:\\Programme\\ICQLite\\ICQLite.exe"=
R2 CTAudSvcService;Creative Audio Service;C:\Programme\Creative\Shared Files\CTAudSvc.exe [2008-03-07 20:24]
R2 LxrSII1d;Secure II Driver;C:\WINDOWS\system32\Drivers\LxrSII1d.sys [2006-12-14 10:37]
R2 NMSAccessU;NMSAccessU;C:\Programme\CDBurnerXP\NMSAccessU.exe [2007-10-12 09:34]
R2 UxTuneUp;TuneUp Designerweiterung;C:\WINDOWS\System32\svchost.exe [2004-08-04 00:58]
R3 ha20x2k;Creative 20X HAL Driver;C:\WINDOWS\system32\drivers\ha20x2k.sys [2008-02-25 10:44]
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;C:\WINDOWS\system32\DRIVERS\RTL8187.sys [2006-06-16 09:30]
S3 TuneUp.Defrag;TuneUp Drive Defrag-Dienst;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-04-14 16:03]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{25584aea-0633-11dd-9107-0018f3645f89}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL DVR/AutoRun.exe start.exe
*Newly Created Service* - CATCHME
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B9482BB3-D290-B4EC-C404-A72331581690}]
C:\WINDOWS\system32\winamp.exe
.
Inhalt des "geplante Tasks" Ordners
"2008-04-19 21:00:00 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Programme\TuneUp Utilities 2008\OneClickStarter.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-19 23:36:21
Windows 5.1.2600 Service Pack 2 NTFS
Scanne versteckte Prozesse...
Scanne versteckte Autostart Einträge...
Scanne versteckte Dateien...
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
**************************************************************************
.
Zeit der Fertigstellung: 2008-04-19 23:37:01
ComboFix-quarantined-files.txt 2008-04-19 21:36:37
ComboFix2.txt 2008-04-18 08:38:47
10 Verzeichnis(se), 5,477,318,656 Bytes frei
12 Verzeichnis(se), 5,493,096,448 Bytes frei