Habe auch noch ein combofix durchlauf gemacht da kam folgendes raus ( vielleicht hilft euch das ja was):
ComboFix 08-06-20.4 - Sebastian 2008-06-24 20:48:12.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1031.18.1138 [GMT 2:00]
ausgeführt von:: C:\Users\Sebastian\Downloads\ComboFix.exe
* Neuer Wiederherstellungspunkt wurde erstellt
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\system32\ACER.exe
.
((((((((((((((((((((((( Dateien erstellt von 2008-05-24 bis 2008-06-24 ))))))))))))))))))))))))))))))
.
2008-06-23 20:54 . 2008-06-23 20:54 0 --a------ C:\Windows\System32\SBRC.dat
2008-06-23 20:54 . 2008-06-23 20:54 0 --a------ C:\Windows\System32\SBFC.dat
2008-06-23 12:54 . 2008-06-23 12:54 0 --a------ C:\Windows\nsreg.dat
2008-06-18 18:43 . 2008-06-18 18:43 <DIR> d-------- C:\Users\Sebastian\AppData\Roaming\Sunbelt Software
2008-06-18 18:42 . 2008-06-18 18:42 <DIR> d-------- C:\Users\All Users\Sunbelt Software
2008-06-18 18:42 . 2008-06-18 18:42 <DIR> d-------- C:\ProgramData\Sunbelt Software
2008-06-18 18:42 . 2008-06-18 18:42 <DIR> d-------- C:\Program Files\Sunbelt Software
2008-06-18 13:53 . 2008-04-23 06:27 1,244,672 --a------ C:\Windows\System32\mcmde.dll
2008-06-18 13:53 . 2008-04-23 06:27 428,032 --a------ C:\Windows\System32\EncDec.dll
2008-06-18 13:53 . 2008-04-23 06:27 292,352 --a------ C:\Windows\System32\psisdecd.dll
2008-06-18 13:53 . 2008-04-23 06:26 218,624 --a------ C:\Windows\System32\psisrndr.ax
2008-06-18 13:53 . 2008-04-23 06:26 80,896 --a------ C:\Windows\System32\MSNP.ax
2008-06-18 13:53 . 2008-04-23 06:26 68,608 --a------ C:\Windows\System32\Mpeg2Data.ax
2008-06-18 13:53 . 2008-04-23 06:26 57,856 --a------ C:\Windows\System32\MSDvbNP.ax
2008-06-15 15:16 . 2008-06-15 15:16 <DIR> d-------- C:\_OTMoveIt
2008-06-15 11:20 . 2008-06-15 11:22 <DIR> d-------- C:\Users\All Users\Lavasoft
2008-06-15 11:20 . 2008-06-15 11:22 <DIR> d-------- C:\ProgramData\Lavasoft
2008-06-15 11:20 . 2008-06-15 11:20 <DIR> d-------- C:\Program Files\Lavasoft
2008-06-15 11:09 . 2008-06-15 11:09 <DIR> d-------- C:\Program Files\CCleaner
2008-06-11 14:24 . 2008-04-29 03:42 220,160 --a------ C:\Windows\System32\drivers\bthport.sys
2008-06-11 14:24 . 2008-04-29 05:50 181,760 --a------ C:\Windows\System32\fsquirt.exe
2008-06-11 14:24 . 2008-04-29 03:42 29,184 --a------ C:\Windows\System32\drivers\BTHUSB.SYS
2008-06-11 14:24 . 2008-04-29 03:42 19,456 --a------ C:\Windows\System32\drivers\bthenum.sys
2008-06-11 14:22 . 2008-04-26 10:02 1,327,104 --a------ C:\Windows\System32\quartz.dll
2008-06-11 14:22 . 2008-05-10 03:21 113,664 --a------ C:\Windows\System32\drivers\rmcast.sys
2008-06-11 14:22 . 2008-05-10 05:30 14,848 --a------ C:\Windows\System32\wshrm.dll
2008-06-01 11:59 . 2008-06-01 11:59 <DIR> d-------- C:\Users\Eltern\AppData\Roaming\PC Suite
2008-05-30 15:14 . 2008-05-30 15:14 0 --ah----- C:\Windows\System32\drivers\Msft_Kernel_ccdcmb_010 05.Wdf
2008-05-29 17:33 . 2008-05-30 15:14 <DIR> d-------- C:\Users\Sebastian\AppData\Roaming\PC Suite
2008-05-29 17:33 . 2008-05-29 17:33 <DIR> d-------- C:\Users\Sebastian\AppData\Roaming\Nokia
2008-05-29 17:33 . 2008-05-30 15:14 <DIR> d-------- C:\Users\All Users\PC Suite
2008-05-29 17:33 . 2008-05-30 15:14 <DIR> d-------- C:\ProgramData\PC Suite
2008-05-29 17:33 . 2008-05-29 17:33 <DIR> d-------- C:\Program Files\DIFX
2008-05-29 17:33 . 2008-05-29 17:33 <DIR> d-------- C:\Program Files\Common Files\PCSuite
2008-05-29 17:33 . 2008-05-29 17:33 <DIR> d-------- C:\Program Files\Common Files\Nokia
2008-05-29 17:33 . 2007-09-17 15:53 21,632 --a------ C:\Windows\System32\drivers\pccsmcfd.sys
2008-05-29 17:32 . 2008-05-29 17:33 <DIR> d----c--- C:\Windows\System32\DRVSTORE
2008-05-29 17:31 . 2008-05-29 17:31 <DIR> d-------- C:\Program Files\PC Connectivity Solution
2008-05-29 17:29 . 2008-05-29 17:33 <DIR> d-------- C:\Program Files\Nokia
2008-05-29 17:29 . 2007-11-29 10:32 48,128 --a------ C:\Windows\System32\nmwcdcls.dll
2008-05-29 17:28 . 2008-05-29 17:28 <DIR> d-------- C:\Users\All Users\Installations
2008-05-29 17:28 . 2008-05-29 17:28 <DIR> d-------- C:\ProgramData\Installations
2008-05-28 13:46 . 2008-03-08 02:37 4,247,552 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-05-28 13:46 . 2008-03-08 06:30 1,686,528 --a------ C:\Windows\System32\gameux.dll
2008-05-26 23:50 . 2008-05-26 23:50 0 --a------ C:\Windows\Irremote.ini
2008-05-25 22:47 . 2008-05-25 22:47 <DIR> d-------- C:\Users\Sebastian\AppData\Roaming\Malwarebytes
2008-05-25 22:47 . 2008-05-25 22:47 <DIR> d-------- C:\Users\All Users\Malwarebytes
2008-05-25 22:47 . 2008-05-25 22:47 <DIR> d-------- C:\ProgramData\Malwarebytes
2008-05-25 22:47 . 2008-05-25 22:47 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-25 22:47 . 2008-05-05 20:46 27,048 --a------ C:\Windows\System32\drivers\mbamcatchme.sys
2008-05-25 22:47 . 2008-05-05 20:46 15,864 --a------ C:\Windows\System32\drivers\mbam.sys
2008-05-25 19:53 . 2008-05-25 19:54 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-24 12:10 . 2008-05-24 12:10 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-24 11:46 . 2008-06-20 00:23 <DIR> d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-05-24 11:46 . 2008-06-20 00:23 <DIR> d-------- C:\ProgramData\Spybot - Search & Destroy
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))) ))))
.
2008-06-24 18:46 57,623,584 --sha-w C:\Windows\system32\drivers\fidbox.dat
2008-06-24 17:58 --------- d-----w C:\ProgramData\Kaspersky Lab
2008-06-23 18:35 776,264 --sha-w C:\Windows\system32\drivers\fidbox.idx
2008-06-22 16:43 --------- d-----w C:\Users\Sebastian\AppData\Roaming\temp
2008-06-19 22:23 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-13 17:41 --------- d-----w C:\Program Files\Windows Mail
2008-05-26 21:52 --------- d-----w C:\ProgramData\Nero
2008-05-26 21:52 --------- d-----w C:\Program Files\Common Files\Nero
2008-05-24 09:40 --------- d-----w C:\ProgramData\Google Updater
2008-05-17 20:31 --------- d-----w C:\Program Files\Solent
2008-05-16 12:40 --------- d-----w C:\ProgramData\Microsoft Help
2008-05-16 09:58 12,632 ----a-w C:\Windows\System32\lsdelete.exe
2008-05-13 13:13 --------- d-----w C:\Program Files\ICQ6
2008-05-12 19:47 --------- d-----w C:\Users\Eltern\AppData\Roaming\Apple Computer
2008-05-12 13:26 --------- d-----w C:\Users\Sebastian\AppData\Roaming\Apple Computer
2008-05-12 12:29 --------- d-----w C:\Program Files\Safari
2008-05-03 21:57 --------- d-----w C:\Program Files\ICQLite
2008-05-03 11:37 --------- d-----w C:\Program Files\Free iPod Video Converter
2008-05-03 09:17 --------- d-----w C:\Program Files\DVDVideoSoft
2008-05-03 09:17 --------- d-----w C:\Program Files\Common Files\DVDVideoSoft
2008-04-30 16:05 --------- d-----w C:\Program Files\San Andreas Mod Installer
2008-04-30 15:55 27,715 ----a-w C:\Users\Sebastian\AppData\Roaming\nvModes.dat
2008-04-29 09:20 15,648 ----a-w C:\Windows\system32\drivers\NSDriver.sys
2008-04-29 09:19 15,648 ----a-w C:\Windows\system32\drivers\Awrtrd.sys
2008-04-29 09:19 12,960 ----a-w C:\Windows\system32\drivers\Awrtpd.sys
2008-04-25 04:23 826,368 ----a-w C:\Windows\System32\wininet.dll
2008-04-25 04:23 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-04-25 04:23 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-04-25 04:22 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-04-21 16:51 103,736 ----a-w C:\Windows\System32\PnkBstrB.exe
2008-04-08 16:59 27,430 ----a-w C:\Users\Eltern\AppData\Roaming\nvModes.dat
2007-12-25 03:18 174 --sha-w C:\Program Files\desktop.ini
.
(((((((((((((((((((((((((((( Autostart Punkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Hinweis* leere Eintrage & legitime Standardeintrage werden nicht angezeigt.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe" [2008-02-02 22:21 68856]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-10 14:56 1232896]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 14:35 125440]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" [2008-04-16 12:53 1079808]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-04-25 16:33 457216]
"Acer Tour"="" []
"eRecoveryService"="" []
"NWEReboot"="" []
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-04-19 23:01 262401]
"MSConfig"="C:\Windows\system32\msconfig.exe" [2006-11-02 11:45 222208]
"WarReg_PopUp"="C:\Acer\WR_PopUp\WarReg_PopUp. exe" [2006-11-05 22:48 57344]
"SBCSTray"="C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe" [2007-12-21 15:30 698864]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2007-08-14 07:11:43 535336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\KASPER~1\KASPER~1.0\r3h ook.dll
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Wind ows^Start Menu^Programs^Startup^Acer VCM.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Acer VCM.lnk
backup=C:\Windows\pss\Acer VCM.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Wind ows^Start Menu^Programs^Startup^BTTray.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BTTray.lnk
backup=C:\Windows\pss\BTTray.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Wind ows^Start Menu^Programs^Startup^Google Updater.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Google Updater.lnk
backup=C:\Windows\pss\Google Updater.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer Tour Reminder]
--a------ 2007-08-01 17:30 151552 C:\Acer\AcerTour\Reminder.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2007-03-08 04:38 40048 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ALaunch]
C:\Acer\ALaunch\AlaunchClient.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVP]
--a------ 2007-06-28 13:51 218376 C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
--a------ 2006-11-21 06:39 107112 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eAudio]
--a------ 2007-06-11 14:54 1286144 C:\Acer\Empowering Technology\eAudio\eAudio.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
--a------ 2007-02-12 15:37 174872 C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ Lite]
--a------ 2006-07-11 12:15 3144800 C:\Program Files\ICQLite\ICQLite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IS CfgWiz]
--a------ 2006-11-21 06:37 46728 C:\Program Files\Common Files\Symantec Shared\OPC\{31011D49-D90C-4da0-878B-78D28AD507AF}\cltUIStb.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-03-30 10:36 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]
--a------ 2007-07-31 03:36 707080 C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 12:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-06-26 09:32 8433664 C:\Windows\system32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-06-26 09:33 81920 C:\Windows\system32\NvMcTray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvSvc]
--a------ 2007-06-26 09:33 86016 C:\Windows\system32\nvsvc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\osCheck]
--a------ 2006-11-21 06:36 22696 C:\Program Files\Norton Internet Security\osCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlayMovie]
--------- 2007-05-24 13:38 206952 C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PLFSet]
--a------ 2007-04-25 13:47 45056 C:\Windows\PLFSet.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-03-28 23:37 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
--a------ 2007-09-04 12:39 4702208 C:\Windows\RtHDVCpl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SetPanel]
C:\Acer\APanel\APanel.cmd
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpyHunter Security Suite]
C:\Program Files\Enigma Software Group\SpyHunter\SHStartup.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-09-25 02:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2008-02-02 22:21 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
--a------ 2007-05-09 07:09 865840 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\FirewallRules]
"{4C580168-126C-42B2-8A8D-044236F383EC}"= C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Acer Arcade Deluxe.exe:Acer Arcade Deluxe
"{CC8249BE-6FB8-4F31-95AD-E9E81BAE84F5}"= C:\Program Files\Acer Arcade Deluxe\VideoMagician\VideoMagician.exe:VideoMagici an
"{0D67F139-56C4-45F4-AFE5-97FB47C652D2}"= C:\Program Files\Acer Arcade Deluxe\HomeMedia\HomeMedia.exe:HomeMedia
"{AE0EBDCB-FE25-44EA-9135-8E43A383D3B1}"= C:\Program Files\Acer Arcade Deluxe\DV Wizard\DV Wizard.exe

V Wizard
"{48CD1CD1-0159-43CD-A12A-769862DC4669}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{0E231EBA-4F1E-43B5-939B-95EA31D570D9}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{501A5CA2-48AF-410E-B770-6D6FCC5F51F5}"= C:\Program Files\Acer Arcade Deluxe\DVDivine\DVDivine.exe

VDivine
"{36186017-4032-4C13-A8E1-3DD9886F82EB}"= C:\Program Files\Acer Arcade Deluxe\Play Movie\PlayMovie.exe:Play Movie
"{3BF959E3-2FCE-48ED-890B-F09C9625A419}"= C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe:Play Movie Resident Program
"{8B96B44E-156A-4581-B0AB-65D6A1E9D993}"= C:\Program Files\Acer\Acer VCM\VC.exe:Acer VCM
"TCP Query User{52B3FA0E-0ADD-431B-AD28-C5FAD5A2F62D}C:\\program files\\icq6\\icq.exe"= UDP:C:\program files\icq6\icq.exe:ICQ Library
"UDP Query User{9E672D7F-5302-4F75-988D-D13ACAE5A5BF}C:\\program files\\icq6\\icq.exe"= TCP:C:\program files\icq6\icq.exe:ICQ Library
"{151119EE-479A-4D36-81EA-E466521C016E}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{EEB6AF3D-263C-41A0-BF3A-65181B3F5EA1}C:\\program files\\icqlite\\icqlite.exe"= UDP:C:\program files\icqlite\icqlite.exe:ICQLite
"UDP Query User{E24BE727-9B47-4C87-8E58-4169F85654B3}C:\\program files\\icqlite\\icqlite.exe"= TCP:C:\program files\icqlite\icqlite.exe:ICQLite
"{6A50EFB2-3359-4989-9BB5-BC82762BB783}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{600C63BF-99DC-4B1C-BEE5-E3A9C51C0055}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|S vc=DFSR:Allow inbound TCP traffic|
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\system32\DRIVERS\klim6.sys [2007-04-04 15:59]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};C:\Program Files\Acer Arcade Deluxe\Play Movie\
000.fcl [2006-11-02 16:51]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
R3 winbondcir;Winbond IR Transceiver;C:\Windows\system32\DRIVERS\winbondcir .sys [2007-04-19 09:09]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\b57nd60x.sys [2007-02-08 09:03]
S3 btwaudio;Bluetooth-Audiogerät;C:\Windows\system32\drivers\btwaudio.sy s [2007-03-29 21:46]
S3 btwavdt;Bluetooth AVDT Service;C:\Windows\system32\drivers\btwavdt.sys [2007-02-27 08:20]
S3 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsd efs\20061025.029\IDSvix86.sys [2006-11-21 06:36]
S4 ALaunchService;ALaunch Service;C:\Acer\ALaunch\ALaunchSvc.exe [2007-01-26 14:24]
S4 Automatisches LiveUpdate - Scheduler;Automatisches LiveUpdate - Scheduler;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2006-11-21 06:40]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
*Newly Created Service* - CATCHME
*Newly Created Service* - COMHOST
.
Inhalt des "geplante Tasks" Ordners
"2008-06-24 18:01:09 C:\Windows\Tasks\User_Feed_Synchronization-{BBAD13B6-16C0-4BCF-BB0B-868EAC5AE927}.job"
- C:\Windows\system32\msfeedssync.exe
.
************************************************** ************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-24 20:52:14
Windows 6.0.6000 NTFS
Scanne versteckte Prozesse...
Scanne versteckte Autostart Einträge...
Scanne versteckte Dateien...
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
************************************************** ************************
.
Zeit der Fertigstellung: 2008-06-24 20:54:14
ComboFix-quarantined-files.txt 2008-06-24 18:53:59
18 Verzeichnis(se), 48,874,082,304 Bytes frei
26 Verzeichnis(se), 48,823,312,384 Bytes frei
257 --- E O F --- 2008-06-24 18:06:39