(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"msnmsgr"="c:\programme\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"ICQ"="c:\programme\ICQ6.5\ICQ.exe" [2009-03-01 172792]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
"NvMediaCenter"="c:\windows\system32\NvMcTray. dll" [2008-05-16 86016]
"BDAgent"="c:\programme\BitDefender\BitDefende r 2009\bdagent.exe" [2009-01-09 741376]
"BitDefender Antiphishing Helper"="c:\programme\BitDefender\BitDefender 2009\IEShow.exe" [2008-10-17 69632]
"ISTray"="c:\programme\Spyware Doctor\pctsTray.exe" [2008-12-08 1173384]
"nwiz"="nwiz.exe" [2008-05-16 c:\windows\system32\nwiz.exe]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-11 c:\windows\LOGI_MWX.EXE]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 c:\windows\soundman.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\dokumente und einstellungen\Melinda\Startmen\Programme\Autostar t\
OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk - c:\programme\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
"vidc.ffds"= ffdshow.ax
"msacm.ac3filter"= ac3filter.acm
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\run-]
"µTorrent"=c:\programme\uTorrent\uTorrent.exe
"RegistryMechanic"=c:\programme\Registry Mechanic\RegMech.exe /H
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
"Steam"="c:\programme\steam\steam.exe" -silent
"MsnMsgr"="c:\programme\Windows Live\Messenger\MsnMsgr.Exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run-]
"Adobe Reader Speed Launcher"="c:\programme\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"TrojanScanner"=c:\programme\Trojan Remover\Trjscan.exe
"PCMService"="c:\programme\CyberLink\PowerCinema\P CMService.exe"
"GrooveMonitor"="c:\programme\Microsoft Office\Office12\GrooveMonitor.exe"
"AVMWlanClient"=c:\programme\avmwlanstick\wlangui. exe
"AdobeCS4ServiceManager"="c:\programme\Gemeins ame Dateien\Adobe\CS4ServiceManager\CS4ServiceManager. exe" -launchedbylogin
"Malwarebytes' Anti-Malware"="c:\programme\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programme\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programme\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Programme\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Programme\\Java\\jre6\\bin\\java.exe"=
"c:\\Programme\\Warcraft III\\Warcraft III.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Programme\\Steam\\steamapps\\karlbvb\\cou nter-strike source\\hl2.exe"=
"c:\\Programme\\FrostWire\\FrostWire.exe"=
"c:\\Programme\\Veoh Networks\\Veoh\\VeohClient.exe"=
"c:\\Programme\\Bonjour\\mDNSResponder.exe"=
"c:\\Programme\\uTorrent\\uTorrent.exe"=
"c:\\Programme\\Zattoo\\zattood.exe"=
"c:\\Programme\\Zattoo\\Zattoo2.exe"=
"c:\\Programme\\FDRLab\\save2pc\\save2pc.exe"=
"c:\\Programme\\Gemeinsame Dateien\\Adobe\\CS4ServiceManager\\CS4ServiceManag er.exe"=
"c:\\Programme\\mIRC\\mirc.exe"=
"c:\\Programme\\Counter-Strike Source\\hl2.exe"=
"c:\\Programme\\Opera\\opera.exe"=
"c:\\Programme\\ICQ6.5\\ICQ.exe"=
"c:\\Programme\\Skype\\Phone\\Skype.exe"=
"c:\\Programme\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programme\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\GloballyOpenPorts\List]
"60140:TCP"= 60140:TCP:k
"60140:UDP"= 60140:UDP:kk
"5353:TCP"= 5353:TCP:Adobe CSI CS4
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-03-19 130424]
R2 BDVEDISK;BDVEDISK;c:\programme\BitDefender\BitDefe nder 2009\BDVEDISK.sys [2008-10-06 82696]
R2 Cap7146_DVB_10;Philips BDA/DVB-S Capture (BSRU6_S);c:\windows\system32\drivers\DVBcap46_10. sys [2008-08-12 56960]
R2 MBAMService;MBAMService;c:\programme\Malwarebytes' Anti-Malware\mbamservice.exe [2008-10-24 170640]
R2 PTuneDVB_10;Philips BDA/DVB-S Tuner (BSRU6_S);c:\windows\system32\drivers\PTuneDVB_10. sys [2008-08-12 52992]
R2 sdAuxService;PC Tools Auxiliary Service;c:\programme\Spyware Doctor\pctsAuxs.exe [2009-03-19 348752]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [2008-12-06 603904]
R3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [2008-09-08 799744]
R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [2008-09-18 111112]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [2009-02-03 104328]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\dr ivers\mbam.sys [2008-10-24 15504]
S2 gupdate1c9a674b3f24aec;Google Update Service (gupdate1c9a674b3f24aec);c:\programme\Google\Updat e\GoogleUpdate.exe [2009-03-16 133104]
S3 Arrakis3;BitDefender Arrakis Server;c:\programme\Gemeinsame Dateien\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe [2008-07-17 118784]
S3 FWLANUSB;AVM FRITZ!WLAN;c:\windows\system32\drivers\fwlanusb.sy s [2008-08-12 265088]
S3 vmfilter303;vmfilter303;c:\windows\system32\driver s\vmfilter303.sys --> c:\windows\system32\drivers\vmfilter303.sys [?]
S3 vvftav303;vvftav303;c:\windows\system32\drivers\vv ftav303.sys [2009-01-31 475136]
S3 ZSMC0303;VIMICRO USB PC Camera (ZC0301PLH);c:\windows\system32\drivers\usbVM303.s ys [2009-01-31 1474560]
--- Andere Dienste/Treiber im Speicher ---
*NewlyCreated* - 688C7962
*NewlyCreated* - EFC40B41
*NewlyCreated* - PCTCORE
*NewlyCreated* - SDAUXSERVICE
*NewlyCreated* - SDCORESERVICE
*Deregistered* - 688c7962
*Deregistered* - efc40b41
*Deregistered* - mchInjDrv
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Inhalt des "geplante Tasks" Ordners
2009-03-19 c:\windows\Tasks\1-Klick-Wartung.job
- c:\programme\TuneUp Utilities 2009\OneClickStarter.exe [2008-11-24 12:32]
2009-03-19 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\programme\Google\Update\GoogleUpdate.exe [2009-03-16 21:20]
.
.
------- Zusätzlicher Suchlauf -------
.
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\programme\PokerStars.NET\PokerStarsUpdate.exe
FF - ProfilePath - c:\dokumente und einstellungen\Paul\Anwendungsdaten\Mozilla\Firefox \Profiles\kufipyyx.default\
FF - prefs.
js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=
FF - component: c:\programme\Google\Google Gears\Firefox\components\gears.dll
FF - component: c:\programme\Mozilla Firefox\components\FFComm.dll
FF - plugin: c:\dokumente und einstellungen\Paul\Anwendungsdaten\Mozilla\Firefox \Profiles\kufipyyx.default\extensions\
firefox@tvunetworks.com\plugins\npTVUAx.dll
FF - plugin: c:\programme\Google\Update\1.2.141.5\npGoogleOneCl ick7.dll
FF - plugin: c:\programme\Microsoft Silverlight\2.0.40115.0\npctrl.1.0.20926.0.dll
FF - plugin: c:\programme\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\programme\Opera\program\plugins\npdivx32.dll
FF - plugin: c:\programme\Veetle\plugins\npVeetle.dll
FF - plugin: c:\programme\Veetle\VLC\npvlc.dll
FF - plugin: c:\programme\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
---- FIREFOX Richtlinien ----
FF - user.
js: network.http.max-persistent-connections-per-server - 4
FF - user.
js: nglayout.initialpaint.delay - 600
FF - user.
js: content.notify.interval - 600000
FF - user.
js: content.max.tokenizing.time - 1800000
FF - user.
js: content.switch.threshold - 600000
.
************************************************** ************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-19 15:58:26
Windows 5.1.2600 Service Pack 3 NTFS
detected NTDLL code modification:
ZwClose
Scanne versteckte Prozesse...
Scanne versteckte Autostarteinträge...
Scanne versteckte Dateien...
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
************************************************** ************************
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
- - - - - - - > 'explorer.exe'(784)
c:\programme\Spyware Doctor\pctgmhk.dll
c:\programme\Logitech\MouseWare\System\LgWndHk.dll
.
Zeit der Fertigstellung: 2009-03-19 16:02:27
ComboFix-quarantined-files.txt 2009-03-19 15:02:22
Vor Suchlauf: 18 Verzeichnis(se), 114.676.314.112 Bytes frei
Nach Suchlauf: 18 Verzeichnis(se), 114,749,005,824 Bytes frei
245 --- E O F --- 2009-03-11 15:28:54