ComboFix 08-01-10.2 - Besitzer 2008-01-10 20:13:08.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1031.18.284 [GMT 1:00]
ausgeführt von:: C:\Dokumente und Einstellungen\Besitzer\Desktop\ComboFix.exe
Command switches used :: C:\Dokumente und Einstellungen\Besitzer\Desktop\cfscript.txt
* Neuer Wiederherstellungspunkt wurde erstellt
FILE
C:\WINDOWS\scvhost.exe
C:\WINDOWS\system32\drivers\pxacaend.sys
C:\WINDOWS\system32\drivers\vxvetfmf.sys
C:\WINDOWS\system32\drivers\xfsalekn.sys
C:\WINDOWS\system32\svchot.exe
.
((((((((((((((((((((((( Dateien erstellt von 2007-12-10 bis 2008-01-10 ))))))))))))))))))))))))))))))
.
2008-01-10 14:39 . 2007-07-30 19:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-01-10 14:38 . 2008-01-10 14:45 <DIR> d-------- C:\WINDOWS\LastGood
2008-01-10 14:38 . 2007-07-30 19:18 34,136 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-01-10 14:38 . 2007-07-30 19:20 30,040 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-01-10 14:38 . 2007-07-30 19:20 30,040 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-01-10 14:38 . 2007-07-30 19:18 20,824 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-01-10 14:31 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-08 22:39 . 2008-01-09 00:37 <DIR> d-------- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Spybot - Search & Destroy
2008-01-08 21:31 . 2008-01-08 21:31 40,448 --a------ C:\WINDOWS\passview3.dll
2008-01-08 21:31 . 2008-01-08 21:31 0 --a------ C:\data3.pwd
2008-01-08 01:19 . 2008-01-08 01:19 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-01-07 02:37 . 2008-01-07 02:37 45,056 --a------ C:\WINDOWS\passview4.dll
2008-01-07 02:36 . 2008-01-07 02:36 52,736 --a------ C:\WINDOWS\passview.dll
2007-12-24 01:49 . 2007-12-24 01:51 2,359,350 --a------ C:\WINDOWS\screenshot.bmp
2007-12-24 01:49 . 2007-12-24 01:49 71,168 --a------ C:\WINDOWS\ijl11.dll
2007-12-24 01:49 . 2007-12-24 01:49 56,512 --a------ C:\WINDOWS\screenshot.jpg
2007-12-23 19:22 . 2007-12-23 19:22 <DIR> d-------- C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Nero
2007-12-23 19:21 . 2007-12-23 19:21 <DIR> d-------- C:\Programme\Nero
2007-12-23 19:21 . 2007-12-23 19:21 <DIR> d-------- C:\Programme\Gemeinsame Dateien\Nero
2007-12-23 19:21 . 2007-12-23 19:21 <DIR> d-------- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Nero
2007-12-23 19:21 . 2006-03-17 11:45 1,757,184 --a------ C:\WINDOWS\system32\imagX7.dll
2007-12-23 19:21 . 2006-03-17 11:45 802,816 --a------ C:\WINDOWS\system32\imagXRA7.dll
2007-12-23 19:21 . 2006-03-17 11:45 497,296 --a------ C:\WINDOWS\system32\imagXpr7.dll
2007-12-23 19:21 . 2006-03-17 14:49 368,640 --a------ C:\WINDOWS\system32\TwnLib4.dll
2007-12-23 19:21 . 2006-03-17 11:45 258,048 --a------ C:\WINDOWS\system32\imagXR7.dll
2007-12-23 19:19 . 2007-12-23 19:19 108,336 --a------ C:\WINDOWS\mswinsck.ocx
2007-12-23 15:44 . 2001-08-18 04:20 97,440 --a------ C:\WINDOWS\system32\drivers\b57xp32.sys
2007-12-23 15:44 . 2001-08-18 04:20 97,440 --a--c--- C:\WINDOWS\system32\dllcache\b57xp32.sys
2007-12-22 11:35 . 2007-12-22 11:35 <DIR> d-------- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Azureus
2007-12-22 11:33 . 2008-01-10 18:13 <DIR> d-------- C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Azureus
2007-12-22 11:32 . 2007-12-23 10:55 <DIR> d-------- C:\Programme\Azureus
2007-12-21 20:55 . 2005-11-02 13:24 424,320 --a------ C:\WINDOWS\system32\drivers\BCMWL5.SYS
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-23 14:33 --------- d--h--w C:\Programme\InstallShield Installation Information
2007-12-23 14:33 --------- d-----w C:\Programme\OO Software
2007-12-23 14:00 --------- d-----w C:\Programme\Dell
2007-12-22 17:57 --------- d-----w C:\Programme\Windows Live Toolbar
2007-12-22 17:55 --------- d-----w C:\Programme\ICQToolbar
2007-11-16 18:43 --------- d-----w C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Sibelius Software
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\RPRSTITL.FOT
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\RPRSTEXT.FOT
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\RPRSSTMP.FOT
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\RPRSSPEC.FOT
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\RPRSSCRP.FOT
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\RPRSREH_.FOT
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\RPRSMET_.FOT
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\RPRSCHOR.FOT
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\RPRS____.FOT
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\OPUSTEXT.FOT
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\OPUSSE__.FOT
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\OPUSS___.FOT
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\OPUSROMC.FOT
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\OPUSPC__.FOT
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\OPUSP___.FOT
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\OPUSO___.FOT
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\OPUSNN__.FOT
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\OPUSM___.FOT
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\OPUSJAPC.FOT
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\OPUSFS__.FOT
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\OPUSFBE_.FOT
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\OPUSFB__.FOT
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\OPUSCSC_.FOT
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\OPUSCS__.FOT
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\OPUSC___.FOT
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\OPUS____.FOT
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\INKPEN2_.FOT
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\INK2TEXT.FOT
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\INK2SPEC.FOT
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\INK2SCRI.FOT
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\INK2METR.FOT
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\INK2CHOR.FOT
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\HELST___.FOT
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\HELSS___.FOT
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\HELSM___.FOT
2007-11-16 18:42 1,409 ----a-w C:\WINDOWS\Fonts\HELSINKI.FOT
2007-11-16 18:42 --------- d-----w C:\Programme\Sibelius Software
2007-11-16 01:14 --------- d-----w C:\Programme\Gemeinsame Dateien\xing shared
2007-11-16 01:14 --------- d-----w C:\Programme\Gemeinsame Dateien\Real
2007-11-16 01:13 --------- d-----w C:\Programme\Real
2007-11-10 11:36 --------- d-----w C:\Programme\iTunes
2007-11-10 11:36 --------- d-----w C:\Programme\iPod
2007-11-10 11:33 --------- d-----w C:\Programme\QuickTime
2003-03-21 11:45 250,544 -c--a-w C:\Programme\Gemeinsame Dateien\keyhelp.ocx
.
((((((((((((((((((((((((((((( snapshot@2008-01-10_14.40.02.32 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-10 13:31:32 233,472 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
+ 2008-01-10 19:12:56 233,472 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
- 2008-01-10 13:31:32 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
+ 2008-01-10 19:12:56 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
- 2008-01-10 13:31:33 229,376 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
+ 2008-01-10 19:12:56 229,376 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
- 2008-01-10 13:31:33 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
+ 2008-01-10 19:12:56 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
- 2008-01-10 13:31:33 5,906,432 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\NTUSER.DAT
+ 2008-01-10 19:12:59 5,910,528 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\NTUSER.DAT
- 2008-01-10 13:31:34 212,992 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
+ 2008-01-10 19:12:59 212,992 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
+ 2005-05-26 03:16:24 75,544 ----a-w C:\WINDOWS\LastGood\system32\cdm.dll
+ 2005-05-26 03:16:22 128,232 ----a-w C:\WINDOWS\LastGood\system32\mucltui.dll
+ 2005-05-26 03:16:24 178,408 ----a-w C:\WINDOWS\LastGood\system32\muweb.dll
+ 2005-05-26 03:16:22 466,200 ----a-w C:\WINDOWS\LastGood\system32\wuapi.dll
+ 2005-05-26 03:16:22 124,696 ----a-w C:\WINDOWS\LastGood\system32\wuauclt.exe
+ 2005-05-26 03:16:30 1,343,768 ----a-w C:\WINDOWS\LastGood\system32\wuaueng.dll
+ 2005-05-26 03:16:22 128,280 ----a-w C:\WINDOWS\LastGood\system32\wucltui.dll
+ 2005-05-26 03:16:30 41,240 ----a-w C:\WINDOWS\LastGood\system32\wups.dll
+ 2005-05-26 03:16:30 18,200 ----a-w C:\WINDOWS\LastGood\system32\wups2.dll
+ 2005-05-26 03:16:30 173,536 ----a-w C:\WINDOWS\LastGood\system32\wuweb.dll
- 2005-05-26 03:16:24 75,544 ----a-w C:\WINDOWS\system32\cdm.dll
+ 2007-07-30 18:19:20 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
- 2005-05-26 03:16:24 75,544 -c--a-w C:\WINDOWS\system32\dllcache\cdm.dll
+ 2007-07-30 18:19:20 92,504 -c--a-w C:\WINDOWS\system32\dllcache\cdm.dll
+ 2007-07-30 18:19:36 549,720 -c--a-w C:\WINDOWS\system32\dllcache\wuapi.dll
- 2005-05-26 03:16:22 124,696 -c--a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
+ 2007-07-30 18:19:16 53,080 -c--a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
- 2005-05-26 03:16:30 1,343,768 -c--a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
+ 2007-07-30 18:19:42 1,712,984 -c--a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
+ 2007-07-30 18:19:32 325,976 -c--a-w C:\WINDOWS\system32\dllcache\wucltui.dll
+ 2007-07-30 18:19:28 203,096 -c--a-w C:\WINDOWS\system32\dllcache\wuweb.dll
- 2005-05-26 03:16:22 128,232 ----a-w C:\WINDOWS\system32\mucltui.dll
+ 2007-07-30 18:19:10 271,224 ----a-w C:\WINDOWS\system32\mucltui.dll
- 2005-05-26 03:16:24 178,408 ----a-w C:\WINDOWS\system32\muweb.dll
+ 2007-07-30 18:19:04 207,736 ----a-w C:\WINDOWS\system32\muweb.dll
- 2008-01-10 12:32:01 76,402 ----a-w C:\WINDOWS\system32\perfc007.dat
+ 2008-01-10 13:41:09 76,402 ----a-w C:\WINDOWS\system32\perfc007.dat
- 2008-01-10 12:32:01 63,464 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-01-10 13:41:09 63,464 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-01-10 12:32:01 419,198 ----a-w C:\WINDOWS\system32\perfh007.dat
+ 2008-01-10 13:41:09 419,198 ----a-w C:\WINDOWS\system32\perfh007.dat
- 2008-01-10 12:32:01 403,862 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-01-10 13:41:09 403,862 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2007-07-30 18:18:40 33,624 ----a-w C:\WINDOWS\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.0.6000.381\wups.dll
+ 2007-07-30 18:19:12 43,352 ----a-w C:\WINDOWS\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.0.6000.381\wups2.dll
- 2005-05-26 03:16:22 466,200 ----a-w C:\WINDOWS\system32\wuapi.dll
+ 2007-07-30 18:19:36 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
- 2005-05-26 03:16:22 124,696 ----a-w C:\WINDOWS\system32\wuauclt.exe
+ 2007-07-30 18:19:16 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
- 2005-05-26 03:16:30 1,343,768 ----a-w C:\WINDOWS\system32\wuaueng.dll
+ 2007-07-30 18:19:42 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll
- 2005-05-26 03:16:22 128,280 ----a-w C:\WINDOWS\system32\wucltui.dll
+ 2007-07-30 18:19:32 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
- 2005-05-26 03:16:30 173,536 ----a-w C:\WINDOWS\system32\wuweb.dll
+ 2007-07-30 18:19:28 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
.
-- Snapshot reset to current date --
.
(((((((((((((((((((((((((((( Autostart Punkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Hinweis* leere Eintrage & legitime Standardeintrage werden nicht angezeigt.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:57 15360]
"msnmsgr"="C:\Programme\MSN Messenger\msnmsgr.exe" [2007-01-19 12:55 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PCTVOICE"="pctspk.exe" [2003-02-24 15:35 163840 C:\WINDOWS\system32\pctspk.exe]
"Apoint"="C:\Programme\Apoint\Apoint.exe" [2003-06-10 23:07 147456]
"mspwr"="C:\WINDOWS\System32\PuXpMan.exe" [2004-06-12 18:51 102400]
"avgnt"="C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe" [2007-10-10 22:29 249896]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 09:35 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 09:32 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 09:36 114688]
"PRONoMgr.exe"="C:\Programme\Intel\NCS\PROSet\PRONoMgr.exe" [2003-05-28 17:32 86016]
"QuickTime Task"="C:\Programme\QuickTime\QTTask.exe" [2007-10-19 20:16 286720]
"iTunesHelper"="C:\Programme\iTunes\iTunesHelper.exe" [2007-11-02 18:36 267048]
"TkBellExe"="C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" [2007-11-16 02:13 185896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"@"="" []
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 00:57 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
C:\WINDOWS\system32\LgNotify.dll 2003-06-20 07:03 110592 C:\WINDOWS\system32\LgNotify.dll
SafeBoot Registrierungsschlüssel muss repariert werden. Dieser PC kann nicht im abgesicherten Modus starten.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
@="Driver Group"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
@="DiskDrive"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
@="Hdc"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
@="Keyboard"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
@="Mouse"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
@="System"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
@="Volume"
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Adobe Acrobat - Schnellstart.lnk]
path=C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Adobe Acrobat - Schnellstart.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat - Schnellstart.lnkCommon Startup
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Microsoft Office.lnk]
path=C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^WinZip Quick Pick.lnk]
path=C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
--a------ 2006-01-12 20:52 483328 C:\Programme\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Auktionsfreundin]
C:\Programme\Auktionsfreundin\Auktionsfreundin.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
--------- 2004-08-04 00:58 110592 C:\WINDOWS\system32\bthprops.cpl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
--a------ 2007-10-22 16:45 177400 C:\Programme\ICQ6\ICQ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-11-02 18:36 267048 C:\Programme\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:55 5674352 C:\Programme\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-10-19 20:16 286720 C:\Programme\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 2007-07-02 16:10 23237416 C:\Programme\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
-ra------ 2005-10-26 17:17 159744 C:\Programme\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-03-14 02:43 83608 C:\Programme\Java\jre1.6.0_01\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WEB.DE_WEB.DE MultiMessenger]
C:\Programme\WEB.DE\WEB.DE Messenger\MESSENGR.exe
R0 avgntmgr;avgntmgr;C:\WINDOWS\system32\drivers\avgntmgr.sys [2007-09-06 21:50]
R1 avgntdd;avgntdd;C:\WINDOWS\system32\DRIVERS\avgntdd.sys [2007-09-06 21:50]
S0 dajxbruh;dajxbruh;C:\WINDOWS\system32\drivers\vxvetfmf.sys []
S0 yiaubrqq;yiaubrqq;C:\WINDOWS\system32\drivers\xfsalekn.sys []
S0 yrhxpxqr;yrhxpxqr;C:\WINDOWS\system32\drivers\pxacaend.sys []
S2 NvNdis;NVIDIA NDIS IO Control Driver;C:\WINDOWS\system32\Drivers\NvNdis.sys []
S3 {E2B953A7-195A-44F9-9BA3-3D5F4E32BB55};AIM 3.0 Part 01 Codec Driver CH-7009-B;C:\WINDOWS\system32\drivers\wA301b.sys [2003-02-15 00:12]
S3 NAL;Nal Service ;C:\WINDOWS\system32\Drivers\iqvw32.sys [2002-11-22 20:01]
S3 PAC207;Trust WB-1200p Mini Webcam;C:\WINDOWS\system32\DRIVERS\pfc027.sys [2005-02-24 12:29]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0274efc2-1387-11dc-bc89-0010c6264b72}]
\Shell\AutoRun\command - G:\START.EXE
.
Inhalt des "geplante Tasks" Ordners
"2007-12-18 14:37:09 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Programme\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-10 20:16:22
Windows 5.1.2600 Service Pack 2 NTFS
Scanne versteckte Prozesse...
Scanne versteckte Autostart Einträge...
Scanne versteckte Dateien...
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
**************************************************************************
.
Zeit der Fertigstellung: 2008-01-10 20:17:18
ComboFix-quarantined-files.txt 2008-01-10 19:17:08
ComboFix2.txt 2008-01-10 13:40:27