@ Nikita
diese datei:
O23 - Service: Taskplaner (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\spools.exe
hat HiJackThis bei mir nicht angezeigt... komisch, aber den rest hab ich so gemacht.
report von SDFix:
Checking Services :
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting
Checking Files :
Trojan Files Found:
C:\Dokumente und Einstellungen\johann\cftmon.exe - Deleted
C:\Dokumente und Einstellungen\LocalService\cftmon.exe - Deleted
C:\WINDOWS\system32\IEBHO.dll - Deleted
C:\WINDOWS\system32\IEBHO03.dll - Deleted
C:\WINDOWS\system32\IEBHO05.dll - Deleted
C:\WINDOWS\system32\IEBHO0F.dll - Deleted
C:\WINDOWS\system32\IEBHO11.dll - Deleted
C:\WINDOWS\system32\IEBHO12.dll - Deleted
C:\WINDOWS\system32\IEBHO1D.dll - Deleted
C:\WINDOWS\system32\IEBHO21.dll - Deleted
C:\WINDOWS\system32\IEBHO25.dll - Deleted
C:\WINDOWS\system32\IEBHO26.dll - Deleted
C:\WINDOWS\system32\IEBHO2B.dll - Deleted
C:\WINDOWS\system32\IEBHO2C.dll - Deleted
C:\WINDOWS\system32\IEBHO2D.dll - Deleted
C:\WINDOWS\system32\IEBHO35.dll - Deleted
C:\WINDOWS\system32\IEBHO3F.dll - Deleted
C:\WINDOWS\system32\IEBHO43.dll - Deleted
C:\WINDOWS\system32\IEBHO5B.dll - Deleted
C:\WINDOWS\system32\IEBHO5C.dll - Deleted
C:\WINDOWS\system32\tmp.exe - Deleted
C:\WINDOWS\system32\drivers\spools.exe - Deleted
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1353.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-29 18:36:39
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\System]
"OODEFRAG10.00.00.01WORKSTATION"="30481166F2A2E562AAA2F11EC50C720DADAEA2C7F8533C13B8E751EB2214597096310EC9CB5C97CBA00E88075AF32AF151F8AA70CC359FDEA03BF7523B6EB85938DEC5D1B65B7A9EF1ABC1676C2BA01A27B43DDDA597D93255FBDCE4868953A10A9A8635AE531461A68125419B73ABA56E4AC377676BAB676992E717CCA9F8FA926C5010807BE2405A5BF478D995935B7764D60CCBACCBFB02AB2FFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A2D97226D213B555BA7FD869164D6794FEBC9E127BECC74C1A571DA4BA7688090855E9E57E98497831E45B0078A62E9974E442B5AF1C155804DC42ED13444279DB7A62694CD681BADDD4B6D613E956C86B08962B993335021E1D634D8996D98E0AC35D150C851B410CD78C17E3B4E5CE303BB5401B98B150A301DF443935921A36606D5612C25ADBE904BFBA9B19431A9D99F11FDC73AEF0B6479A48E48076A4E9552590D9C1C8100AC035B08C3E984CEC9223E129001A3EDA037D42F0E651EA14789E187F483494E3CC575D2CDFD3393EE42498710F204EF71B718E656F32DA85F775B7C6312C594FB7139697CC28EB9427D2C8488537655ACA69FD6FB26E187251CBAE936907FA8D665A270D698AA1D7C4126AE659947F331F56575FDD1DF976D9C52D72755D503E12234EEE2CB54CD2F9C7E6A898B24A96FBAFD12C329B8D8CB80B590F698C606A47E5BF449FA71035D9DFA10DE4D3A8FC1A739CED050A9098E8C8CE3CF035E9F966A122B76422479248C76CB7EEF63042019F5660C0CA775E3CB01AEE49BDDA3D25D611192DAB7F627F73117102E6ACA7103815E46108E886D475BD42464F5A668B0C9A5B410F7A7F0F59C92679AB9C527C446101F6AC42A0AA522FF3CB55BF0B764A42147CD82DAAD7F24765C49731C74A5139DC2A69119C8A81D965D58216269620FD7E4CDC41858E40ADE369BBD2F656EB0DC631329AD092449A1E724BA015711FBAFAB6B09519BDC29577FEEE9A30CDABC1ADDB3F55F53860444544E8D19B5EDB568AD02EB9CE43020A9D32CD57A5B3253128898C6C29429D9B2A815853E08B7124D547F3F37850080CF543378CF2DF74A76DAEDA406CCCC8DBBEF3DB80ECF87B6BA557633EC66CE30E45854D6F92FC3A65DCD72EE325C7B13399F876EA2FFB9D66EA57A3C5D3EEA879F062786AE3881AA1751FCD1F9DF62F42F284F3D7F9BD7C4438AB1FEB9987EB2B07D6621EADD5BA835BB8C66E01F197202A1CDF3E05B842A9425281C6F737C870B770FBDA978CC828D967E87EE1A3C8D7405A8B4B68419CAAE658BF1EB154DD8F5656F6A72DA6F2225C854835B64D23E45C6C8CDEA3F83CD5A3E08E72EE08CEC059BF4B3FDF72EDF4F3FE3DAAD6028A3B47173B8E1A5A58A69B"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{6D5DAABE-0E1C-12C0-B84E-F9C75D925BD2}]
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Programme\\ICQLite\\ICQLite.exe"="C:\\Programme\\ICQLite\\ICQLite.exe:*:Enabled:ICQ Lite"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
Remaining Files :
File Backups: - C:\PROGRA~1\SDFix\backups\backups.zip
Files with Hidden Attributes :
Mon 9 Feb 2004 15,360 A..HR --- "C:\WINDOWS\system32\drivers\NetMotCM.sys"
Finished!
Combo Fix Report
((((((((((((((((((((((( Dateien erstellt von 2008-03-28 bis 2008-04-29 ))))))))))))))))))))))))))))))
.
2008-04-29 18:47 . 2008-04-29 18:47 <DIR> d-------- C:\Programme\CCleaner
2008-04-29 18:26 . 2008-04-29 18:26 <DIR> d-------- C:\WINDOWS\ERUNT
2008-04-29 18:20 . 2008-04-29 18:52 <DIR> d-------- C:\Programme\Antivir
2008-04-29 17:32 . 2008-04-29 18:40 <DIR> d-------- C:\Programme\SDFix
2008-04-29 17:25 . 2008-04-29 17:25 <DIR> d-------- C:\Programme\backups
2008-04-28 14:53 . 2008-04-29 18:10 5,120 --a------ C:\Dokumente und Einstellungen\johann\ftp33.dll
2008-04-26 11:51 . 2008-04-26 11:51 <DIR> d-------- C:\Programme\Avira
2008-04-26 11:40 . 2008-04-26 11:45 22,322,568 --a------ C:\Programme\antivir_workstation8_winu_de_h.exe
2008-04-26 11:26 . 2008-04-26 11:26 <DIR> d-------- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Avira
2008-04-26 11:09 . 2007-04-17 11:32 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-04-26 11:09 . 2007-03-08 07:09 1,040,384 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-04-26 11:09 . 2008-03-01 14:53 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-04-26 11:09 . 2008-03-01 14:53 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-04-26 11:09 . 2008-03-01 14:53 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-04-26 11:09 . 2008-03-01 14:53 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-04-26 11:09 . 2008-03-01 14:53 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-04-26 11:09 . 2008-02-22 12:00 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-04-26 11:08 . 2008-03-01 14:53 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-04-25 17:19 . 2008-04-25 17:19 401,720 --a------ C:\Programme\HiJackThis.exe
2008-04-25 17:12 . 2008-04-26 14:05 <DIR> d-------- C:\WINDOWS\system32\de-de
2008-04-25 16:59 . 2006-02-28 14:00 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-04-25 16:54 . 2008-04-25 16:54 206 --a------ C:\WINDOWS\system32\MRT.INI
2008-04-24 18:00 . 2006-09-06 17:42 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-04-22 15:14 . 2008-04-22 15:19 <DIR> d-------- C:\Programme\EA SPORTS
2008-04-17 19:17 . 2008-04-17 21:01 <DIR> d-------- C:\Dokumente und Einstellungen\johann\.housecall6.6
2008-04-17 19:12 . 2008-04-17 19:12 <DIR> d-------- C:\WINDOWS\Sun
2008-04-17 19:12 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-04-17 19:11 . 2008-04-17 19:12 <DIR> d-------- C:\Programme\Java
2008-04-17 19:08 . 2008-04-17 19:08 <DIR> d-------- C:\Programme\Gemeinsame Dateien\Java
2008-04-16 14:06 . 2008-04-29 18:10 5,120 --a------ C:\WINDOWS\system32\ftp33.dll
2008-04-14 19:03 . 2008-04-29 18:40 <DIR> d-------- C:\Dokumente und Einstellungen\johann\Anwendungsdaten\OpenOffice.org2
2008-04-14 19:01 . 2008-04-14 19:01 <DIR> d-------- C:\Programme\OpenOffice.org 2.4
2008-04-05 10:04 . 2008-04-05 10:04 <DIR> d---s---- C:\Dokumente und Einstellungen\johann\UserData
2008-04-01 21:54 . 2008-04-11 04:51 101 --a------ C:\WINDOWS\CMMIXER.INI
2008-04-01 18:32 . 2008-04-28 17:21 <DIR> d-------- C:\Programme\Soulseek
5 Datei(en) . 4,724,929 C:\ComboFix\Bytes
3 Datei(en) . 28,946,664 C:\ComboFix\Bytes
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-23 11:57 --------- d-----w C:\Programme\NBA Live 2008
2008-04-07 15:43 --------- d-----w C:\Programme\Opera
2008-04-01 20:38 --------- d-----w C:\Programme\Sharing
2008-03-20 08:03 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-12 13:22 --------- d-----w C:\Programme\ElsterFormular
2008-03-12 13:22 --------- d-----w C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ElsterFormular
2008-03-10 18:28 --------- d-----w C:\Dokumente und Einstellungen\johann\Anwendungsdaten\Hamachi
2008-03-09 22:00 25,280 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys
2008-03-05 17:10 --------- d--h--w C:\Programme\InstallShield Installation Information
2008-03-05 17:08 --------- d-----w C:\Programme\Elster Steuererklärung
2008-03-01 12:54 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-20 06:50 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:33 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-02 16:40 6,222,376 ----a-w C:\Programme\DivXWebPlayerInstaller.exe
2001-08-18 12:00 5,020 ----a-w C:\WINDOWS\inf\61883.tmp
.
(((((((((((((((((((((((((((( Autostart Punkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Hinweis* leere Eintrage & legitime Standardeintrage werden nicht angezeigt.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 14:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"C-Media Mixer"="Mixer.exe" [2001-11-15 12:08 1216512 C:\WINDOWS\mixer.exe]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2005-06-06 19:05 2614496]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-12-20 00:21 196608]
"SunJavaUpdateSched"="C:\Programme\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"avgnt"="C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2006-02-28 14:00 15360]
C:\Dokumente und Einstellungen\johann\Startmen