ComboFix 08-01-23.2 - 00000 2008-01-24 15:33:49.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1031.18.126 [GMT 1:00]
ausgeführt von:: D:\Dokumente und Einstellungen\00000\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\Autorun.inf
.
((((((((((((((((((((((( Dateien erstellt von 2007-12-24 bis 2008-01-24 ))))))))))))))))))))))))))))))
.
2008-01-24 15:26 . 2000-08-31 08:00 51,200 --a------ D:\WINDOWS\Nircmd.exe
2008-01-24 10:25 . 2008-01-24 10:25 230 --a------ D:\WINDOWS\system32\spupdsvc.inf
2008-01-23 23:12 . 2007-05-30 13:10 10,872 --a------ D:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-01-23 22:48 . 2008-01-23 23:10 <DIR> d-------- D:\Programme\SUPERAntiSpyware
2008-01-23 22:42 . 2008-01-23 22:42 <DIR> d-------- D:\Programme\Trend Micro
2008-01-23 19:31 . 2008-01-23 19:35 <DIR> d-------- D:\WINDOWS\BDOSCAN8
2008-01-23 18:12 . 2008-01-23 18:12 <DIR> d-------- D:\Programme\FreshDevices
2008-01-23 17:27 . 2005-08-27 02:38 1,435,272 --a------ D:\WINDOWS\system32\Flash.ocx
2008-01-23 17:27 . 2003-11-19 13:59 512,688 --a------ D:\WINDOWS\system32\XceedCry.dll
2008-01-23 17:27 . 2004-05-11 09:56 423,784 --a------ D:\WINDOWS\system32\XceedBkp.dll
2008-01-23 17:27 . 2004-02-05 20:53 389,120 --a------ D:\WINDOWS\system32\ACTSKN43.OCX
2008-01-23 17:27 . 2004-01-09 10:54 188,416 --a------ D:\WINDOWS\system32\actsplash.ocx
2008-01-23 17:27 . 2004-03-08 23:00 131,856 --a------ D:\WINDOWS\system32\MSADODC.ocx
2008-01-23 17:27 . 2001-03-28 22:02 89,088 --a------ D:\WINDOWS\system32\ProgressBar4.ocx
2008-01-23 17:27 . 1999-01-26 19:36 11,012 --a------ D:\WINDOWS\system32\threadapi.tlb
2008-01-23 17:17 . 2003-04-02 13:00 68,608 --a------ D:\WINDOWS\system32\plugin.ocx
2008-01-23 17:17 . 2003-04-02 13:00 68,608 --a------ D:\WINDOWS\system32\dllcache\plugin.ocx
2008-01-23 17:04 . 2008-01-24 15:22 4,958,588 --a------ D:\WINDOWS\{00000002-00000000-00000000-00001102-00000004-20021102}.BAK
2008-01-23 17:03 . 2008-01-23 17:19 1,374 --a------ D:\WINDOWS\imsins.BAK
2008-01-23 15:02 . 2008-01-23 17:56 <DIR> d-------- D:\Programme\Scr axis mags
2008-01-23 15:01 . 2008-01-23 17:55 <DIR> d-------- D:\Programme\Messenger Plus! Live
2008-01-23 15:01 . 2008-01-23 18:02 <DIR> d-------- D:\Programme\Circle Developement
2008-01-23 12:54 . 2008-01-23 12:54 249,856 --------- D:\WINDOWS\Setup1.exe
2008-01-23 12:54 . 2008-01-23 12:54 73,216 --a------ D:\WINDOWS\ST6UNST.EXE
2008-01-23 11:46 . 2008-01-23 11:47 124 --a------ D:\WINDOWS\vdj.eq
2008-01-23 11:45 . 2005-11-30 21:20 2,314,332 --a------ D:\WINDOWS\system32\LIBMMD.DLL
2008-01-23 11:45 . 1998-06-23 22:00 609,584 --a------ D:\WINDOWS\system32\comctl32.ocx
2008-01-22 19:20 . 2008-01-22 19:20 50 --a------ D:\WINDOWS\winzipme.ini
2008-01-22 18:39 . 2008-01-22 18:39 4,913,803 --a------ D:\Temp\FreeYouTubeToMP3Converter.exe
2008-01-22 18:38 . 2008-01-23 17:56 <DIR> d-------- D:\Temp
2008-01-22 18:37 . 2008-01-23 18:02 <DIR> d-------- D:\Programme\Gemeinsame Dateien\DVDVideoSoft
2008-01-22 18:37 . 2008-01-23 18:02 <DIR> d-------- D:\Programme\DVDVideoSoft
2008-01-22 01:08 . 2008-01-23 17:56 <DIR> d-------- D:\Programme\MSECACHE
2008-01-21 16:57 . 2008-01-23 17:56 <DIR> d-------- D:\Programme\Microsoft Silverlight
2008-01-21 16:46 . 2008-01-23 17:56 <DIR> d-------- D:\WINDOWS\Performance
2008-01-21 16:11 . 2008-01-24 14:31 <DIR> d-------- D:\Programme\PokerStars
2008-01-20 17:24 . 2008-01-23 18:02 <DIR> d-------- D:\Programme\Gemeinsame Dateien\Adobe
2008-01-20 11:20 . 2008-01-20 11:20 360,064 --a------ D:\WINDOWS\system32\drivers\TCPIP.SYS.ORIGINAL
2008-01-20 08:49 . 2006-06-22 17:32 606,208 --a------ D:\WINDOWS\system32\webview.dll
2008-01-20 08:48 . 2008-01-20 08:48 112,690 --------- D:\WINDOWS\hpoins07.dat.temp
2008-01-20 08:48 . 2005-06-22 04:25 17,505 --------- D:\WINDOWS\hpomdl07.dat.temp
2008-01-20 01:53 . 2008-01-23 18:00 <DIR> d-------- D:\WINDOWS\system32\quicktime
2008-01-20 01:53 . 2008-01-23 18:02 <DIR> d-------- D:\Programme\AVI Codec Pack
2008-01-18 15:43 . 2008-01-23 17:59 <DIR> d-------- D:\WINDOWS\Sun
2008-01-18 14:46 . 2007-08-31 22:04 10,880 --a------ D:\WINDOWS\system32\drivers\NdisIP.sys
2008-01-18 14:46 . 2007-08-31 22:04 10,880 --a--c--- D:\WINDOWS\system32\dllcache\ndisip.sys
2008-01-18 14:46 . 2007-08-31 21:57 5,504 --a------ D:\WINDOWS\system32\drivers\MSTEE.sys
2008-01-18 14:46 . 2007-08-31 21:57 5,504 --a--c--- D:\WINDOWS\system32\dllcache\mstee.sys
2008-01-18 14:44 . 2008-01-23 17:55 <DIR> d-------- D:\Programme\IVT Corporation
2008-01-18 14:44 . 2004-09-21 18:18 148,830 --a------ D:\WINDOWS\system32\drivers\bcbthub.sys
2008-01-17 22:53 . 2008-01-23 17:56 <DIR> d-------- D:\Programme\QuickTime
2008-01-17 22:53 . 2008-01-23 18:02 <DIR> d-------- D:\Programme\Apple Software Update
2008-01-17 22:52 . 2008-01-23 17:55 <DIR> d-------- D:\Programme\InterVideo Information Service
2008-01-17 22:52 . 2008-01-23 17:54 <DIR> d-------- D:\Programme\Gemeinsame Dateien\Ulead
2008-01-17 22:52 . 2006-05-11 18:41 654 --------- D:\WINDOWS\remove.iss
2008-01-17 22:51 . 2008-01-23 18:02 <DIR> d-------- D:\Programme\Gemeinsame Dateien\InterVideo
2008-01-17 22:48 . 2008-01-22 02:12 <DIR> d--h----- D:\WINDOWS\msdownld.tmp
2008-01-17 22:46 . 2006-03-20 21:07 5,693,440 --a------ D:\Programme\mplayerc.exe
2008-01-15 23:25 . 2008-01-16 09:33 <DIR> d--h----- D:\WINDOWS\Icons
2008-01-15 23:17 . 2008-01-16 07:22 2,330,496 --a------ D:\WINDOWS\system32\TUKernel.exe
2008-01-15 09:31 . 2008-01-24 15:22 31,056 --a------ D:\WINDOWS\system32\BMXStateBkp-{00000002-00000000-00000000-00001102-00000004-20021102}.rfx
2008-01-15 09:31 . 2008-01-24 15:22 31,056 --a------ D:\WINDOWS\system32\BMXState-{00000002-00000000-00000000-00001102-00000004-20021102}.rfx
2008-01-15 09:31 . 2008-01-24 15:22 30,528 --a------ D:\WINDOWS\system32\BMXCtrlState-{00000002-00000000-00000000-00001102-00000004-20021102}.rfx
2008-01-15 09:31 . 2008-01-24 15:22 30,528 --a------ D:\WINDOWS\system32\BMXBkpCtrlState-{00000002-00000000-00000000-00001102-00000004-20021102}.rfx
2008-01-15 09:31 . 2008-01-24 15:22 11,564 --a------ D:\WINDOWS\system32\DVCState-{00000002-00000000-00000000-00001102-00000004-20021102}.rfx
2008-01-15 09:31 . 2008-01-24 15:22 1,080 --a------ D:\WINDOWS\system32\settingsbkup.sfm
2008-01-15 09:31 . 2008-01-24 15:22 1,080 --a------ D:\WINDOWS\system32\settings.sfm
2008-01-15 09:30 . 2008-01-23 17:59 <DIR> d-------- D:\WINDOWS\system32\Defaults
2008-01-15 09:30 . 2008-01-24 15:22 4,958,588 --a------ D:\WINDOWS\{00000002-00000000-00000000-00001102-00000004-20021102}.CDF
2008-01-15 09:30 . 2000-12-05 09:11 4,174,814 --------- D:\WINDOWS\system32\CT4MGM.SF2
2008-01-15 09:29 . 2008-01-15 09:29 409,600 --a------ D:\WINDOWS\system32\wrap_oal.dll
2008-01-15 09:29 . 2008-01-15 09:29 86,016 --a------ D:\WINDOWS\system32\OpenAL32.dll
2008-01-15 09:28 . 2008-01-23 17:59 <DIR> d-------- D:\WINDOWS\system32\Data
2008-01-15 09:28 . 2006-08-11 15:14 86,446 --a------ D:\WINDOWS\system32\instwdm.ini
2008-01-15 09:28 . 2005-02-17 17:22 24,576 --a------ D:\WINDOWS\CTXFIGER.DLL
2008-01-15 09:28 . 2004-07-30 14:46 20,480 --a------ D:\WINDOWS\INRESGER.DLL
2008-01-15 09:28 . 2005-06-21 12:01 11,264 --a------ D:\WINDOWS\CTDCRGER.DLL
2008-01-15 09:28 . 2006-08-11 14:32 191 --a------ D:\WINDOWS\system32\ctzapxx.ini
2008-01-15 09:18 . 2008-01-23 18:02 <DIR> d-------- D:\Programme\Creative
2008-01-15 08:20 . 2008-01-23 17:56 <DIR> d-------- D:\Programme\TuneUp Utilities 2008
2008-01-15 08:20 . 2008-01-23 23:10 <DIR> d-------- D:\Programme\Gemeinsame Dateien\Wise Installation Wizard
2008-01-15 08:20 . 2008-01-15 08:20 306,432 --a------ D:\WINDOWS\system32\TuneUpDefragService.exe
2008-01-15 08:20 . 2007-12-20 10:41 29,440 --a------ D:\WINDOWS\system32\uxtuneup.dll
2008-01-15 08:00 . 2007-08-31 21:58 10,240 --------- D:\WINDOWS\system32\drivers\sffp_mmc.sys
2008-01-15 08:00 . 2007-08-31 21:58 9,472 --------- D:\WINDOWS\system32\drivers\dumpdrv.sys
2008-01-14 22:07 . 2008-01-23 17:56 <DIR> d-------- D:\Programme\Microsoft Works
2008-01-14 22:06 . 2008-01-23 17:56 <DIR> d-------- D:\Programme\Microsoft.NET
2008-01-14 22:04 . 2008-01-23 17:58 <DIR> d-------- D:\WINDOWS\SHELLNEW
2008-01-14 22:03 . 2008-01-14 22:03 <DIR> dr-h----- D:\MSOCache
2008-01-14 15:57 . 2008-01-23 17:56 <DIR> d-------- D:\Programme\MSXML 4.0
2008-01-14 14:24 . 2007-07-30 19:19 271,224 --a------ D:\WINDOWS\system32\mucltui.dll
2008-01-14 14:24 . 2007-07-30 19:19 207,736 --a------ D:\WINDOWS\system32\muweb.dll
2008-01-14 14:24 . 2007-07-30 19:18 30,072 --a------ D:\WINDOWS\system32\mucltui.dll.mui
2008-01-14 09:55 . 2008-01-14 09:55 268 --ah----- D:\sqmdata07.sqm
2008-01-14 09:55 . 2008-01-14 09:55 244 --ah----- D:\sqmnoopt07.sqm
2008-01-14 09:46 . 2008-01-14 09:46 268 --ah----- D:\sqmdata06.sqm
2008-01-14 09:46 . 2008-01-14 09:46 244 --ah----- D:\sqmnoopt06.sqm
2008-01-14 09:31 . 2008-01-14 09:31 268 --ah----- D:\sqmdata05.sqm
2008-01-14 09:31 . 2008-01-14 09:31 244 --ah----- D:\sqmnoopt05.sqm
2008-01-14 09:26 . 2008-01-14 09:26 268 --ah----- D:\sqmdata04.sqm
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-23 17:02 --------- d-----w D:\Programme\Gemeinsame Dateien\SpeechEngines
2008-01-23 17:02 --------- d-----w D:\Programme\Gemeinsame Dateien\ODBC
2008-01-23 17:02 --------- d-----w D:\Programme\Gemeinsame Dateien\MSSoap
2008-01-23 17:02 --------- d-----w D:\Programme\Gemeinsame Dateien\InstallShield
2008-01-23 17:02 --------- d-----w D:\Programme\Gemeinsame Dateien\Dienste
2008-01-23 17:02 --------- d-----w D:\Programme\avmwlanstick
2008-01-23 17:02 --------- d-----w D:\Programme\ATI Technologies
2008-01-23 17:02 --------- d-----w D:\Programme\ATI
2008-01-23 16:55 --------- d-----w D:\Programme\microsoft frontpage
2008-01-23 14:30 --------- d--h--w D:\Programme\InstallShield Installation Information
2008-01-20 10:23 360,064 ----a-w D:\WINDOWS\system32\drivers\TCPIP.SYS
2008-01-13 19:50 23,600 ----a-w D:\WINDOWS\system32\drivers\TVICHW32.SYS
2008-01-13 19:04 --------- d--h--w D:\Programme\Uninstall Information
2007-12-20 00:04 97,360 ----a-w D:\WINDOWS\system32\drivers\Fwusb1b.bin
2007-12-20 00:04 74,240 ----a-w D:\WINDOWS\system32\fwlanci.dll
2007-12-20 00:04 265,088 ----a-w D:\WINDOWS\system32\drivers\fwlanusb.sys
2007-11-30 22:57 43,696 ----a-w D:\WINDOWS\system32\drivers\srtspx.sys
2007-11-30 22:57 317,616 ----a-w D:\WINDOWS\system32\drivers\srtspl.sys
2007-11-30 22:57 279,088 ----a-w D:\WINDOWS\system32\drivers\srtsp.sys
2007-11-30 22:57 10,549 ----a-w D:\WINDOWS\system32\drivers\srtspx.cat
2007-11-30 22:57 10,549 ----a-w D:\WINDOWS\system32\drivers\srtspl.cat
2007-11-30 22:57 10,545 ----a-w D:\WINDOWS\system32\drivers\srtsp.cat
2007-11-30 22:57 1,430 ----a-w D:\WINDOWS\system32\drivers\srtspl.inf
2007-11-30 22:57 1,421 ----a-w D:\WINDOWS\system32\drivers\srtspx.inf
2007-11-30 22:57 1,415 ----a-w D:\WINDOWS\system32\drivers\srtsp.inf
2007-11-07 09:27 729,600 ----a-w D:\WINDOWS\system32\lsasrv.dll
2007-10-30 18:55 625,032 ----a-w D:\WINDOWS\system32\SymNeti.dll
2007-10-30 18:55 242,056 ----a-w D:\WINDOWS\system32\SymRedir.dll
2007-10-29 22:42 1,293,312 ----a-w D:\WINDOWS\system32\quartz.dll
2007-10-25 08:28 222,720 ----a-w D:\WINDOWS\system32\wmasf.dll
.
(((((((((((((((((((((((((((( Autostart Punkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Hinweis* leere Eintrage & legitime Standardeintrage werden nicht angezeigt.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="D:\WINDOWS\system32\ctfmon.exe" [2007-09-01 03:53 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"osCheck"="D:\Programme\Norton AntiVirus\osCheck.exe" [2006-09-05 22:22 26248]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 09:06 88363 D:\WINDOWS\AGRSMMSG.exe]
"ccApp"="D:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe" [2006-09-03 04:04 84640]
"AVMWlanClient"="D:\Programme\avmwlanstick\wlangui.exe" [2007-12-20 01:04 1748992]
"AtiPTA"="atiptaxx.exe" [2006-02-22 02:05 344064 D:\WINDOWS\system32\atiptaxx.exe]
"SunJavaUpdateSched"="D:\Programme\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"CTHelper"="CTHELPER.EXE" [2006-08-11 14:56 17920 D:\WINDOWS\CTHELPER.EXE]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-08-11 14:56 18944 D:\WINDOWS\system32\CTXFIHLP.EXE]
"ISUSPM"="D:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 17:34 213936]
"Adobe Reader Speed Launcher"="D:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"QuickTime Task"="D:\Programme\QuickTime\qttask.exe" [2006-09-01 15:57 282624]
"!AVG Anti-Spyware"="D:\Programme\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="D:\WINDOWS\System32\CTFMON.EXE" [2007-09-01 03:53 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="D:\\WINDOWS\\system32\\logonui.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AtiTrayTools]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="D:\Programme\QuickTime\qttask.exe" -atboottime
R2 UxTuneUp;TuneUp Designerweiterung;D:\WINDOWS\System32\svchost.exe [2007-09-01 03:53]
R3 FWLANUSB;AVM FRITZ!WLAN;D:\WINDOWS\system32\DRIVERS\fwlanusb.sys [2007-12-20 01:04]
S3 kxwdmdrv;kX WDM Driver Service;D:\WINDOWS\system32\drivers\kx.sys [2004-02-16 23:19]
S3 TuneUp.Defrag;TuneUp Drive Defrag-Dienst;D:\WINDOWS\System32\TuneUpDefragService.exe [2008-01-15 08:20]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
*Newly Created Service* - PROCEXP90
.
Inhalt des "geplante Tasks" Ordners
"2008-01-24 14:00:00 D:\WINDOWS\Tasks\AF373151918CA30D.job"
- d:\dokume~1\00000\anwend~1\scraxi~1\RoamStoreOnce.exe
"2008-01-23 16:49:21 D:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- D:\Programme\Apple Software Update\SoftwareUpdate.exe
"2008-01-18 19:00:20 D:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - 00000.job"
- D:\PROGRA~1\NORTON~1\Navw32.exel/TASK:
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-24 15:35:59
Windows 5.1.2600 Service Pack 3, v.3205 NTFS
Scanne versteckte Prozesse...
Scanne versteckte Autostart Einträge...
Scanne versteckte Dateien...
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
**************************************************************************
.