könntet ihr mir bitte mit der hijack auswertung helfen |
||
---|---|---|
#0
| ||
24.10.2008, 14:47
...neu hier
Beiträge: 3 |
||
|
||
24.10.2008, 16:52
Member
Beiträge: 3716 |
||
|
||
25.10.2008, 16:34
...neu hier
Themenstarter Beiträge: 3 |
#3
ComboFix 08-10-23.08 - Kostja 2008-10-25 15:19:06.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1251.7.1031.18.1543 [GMT 2:00] Running from: D:\firefox download\ComboFix.exe [COLOR=RED]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/COLOR] . Error: Cfiles.dat ((((((((((((((((((((((((( Files Created from 2008-09-25 to 2008-10-25 ))))))))))))))))))))))))))))))) . 2008-10-25 00:10 . 2008-04-13 20:45 26,112 --a------ C:\WINDOWS\system32\drivers\usbser.sys 2008-10-25 00:10 . 2008-04-13 20:45 26,112 --a--c--- C:\WINDOWS\system32\dllcache\usbser.sys 2008-10-25 00:10 . 2008-10-25 00:10 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf 2008-10-25 00:10 . 2008-10-25 00:10 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf 2008-10-24 15:42 . 2008-10-24 15:42 <DIR> d-------- C:\DVDVideoSoft 2008-10-24 15:41 . 2008-10-24 15:41 <DIR> d-------- C:\Programme\Gemeinsame Dateien\DVDVideoSoft 2008-10-24 15:41 . 2008-10-24 15:41 <DIR> d-------- C:\Programme\DVDVideoSoft 2008-10-24 12:18 . 2008-10-24 12:18 <DIR> d-------- C:\Programme\Trend Micro 2008-10-24 12:00 . 2008-10-24 12:00 <DIR> d-------- C:\Programme\Malwarebytes' Anti-Malware 2008-10-24 12:00 . 2008-10-24 12:00 <DIR> d-------- C:\Dokumente und Einstellungen\Kostja\Anwendungsdaten\Malwarebytes 2008-10-24 12:00 . 2008-10-24 12:00 <DIR> d-------- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes 2008-10-24 12:00 . 2008-10-22 16:10 38,496 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys 2008-10-24 12:00 . 2008-10-22 16:10 15,504 --a------ C:\WINDOWS\system32\drivers\mbam.sys 2008-10-24 11:51 . 2008-10-24 11:51 <DIR> d-------- C:\Programme\CCleaner 2008-10-24 11:16 . 2008-10-15 18:35 337,408 -----c--- C:\WINDOWS\system32\dllcache\netapi32.dll 2008-10-21 10:31 . 2008-10-21 10:31 <DIR> d-------- C:\WINDOWS\system32\csShared 2008-10-21 10:31 . 2008-10-21 10:31 <DIR> d-------- C:\Programme\Cornelsen 2008-10-21 10:31 . 2002-03-13 13:15 131,072 --a------ C:\WINDOWS\system32\mupprxmgr10.dll 2008-10-21 10:31 . 2002-03-13 13:15 57,344 --a------ C:\WINDOWS\system32\mupkernps11.dll 2008-10-21 10:30 . 2008-10-21 10:31 <DIR> d-------- C:\Programme\Gemeinsame Dateien\SciFace 2008-10-15 15:39 . 2008-09-15 17:24 1,846,528 -----c--- C:\WINDOWS\system32\dllcache\win32k.sys 2008-10-15 15:39 . 2008-09-08 12:41 333,824 -----c--- C:\WINDOWS\system32\dllcache\srv.sys 2008-10-15 15:38 . 2008-08-14 15:19 2,191,488 -----c--- C:\WINDOWS\system32\dllcache\ntoskrnl.exe 2008-10-15 15:38 . 2008-08-14 15:19 2,147,840 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlmp.exe 2008-10-15 15:38 . 2008-08-14 15:19 2,068,352 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlpa.exe 2008-10-15 15:38 . 2008-08-14 15:19 2,026,496 -----c--- C:\WINDOWS\system32\dllcache\ntkrpamp.exe 2008-10-14 17:43 . 2006-01-19 23:10 363,008 -ra------ C:\WINDOWS\system32\drivers\rt61.sys 2008-10-14 17:12 . 2008-10-14 17:12 <DIR> d-------- C:\Dokumente und Einstellungen\Kostja\Anwendungsdaten\Corel 2008-10-14 17:12 . 2008-10-14 17:12 374 --a------ C:\WINDOWS\capture.ini 2008-10-14 16:58 . 2008-10-14 16:58 <DIR> d-------- C:\WINDOWS\system32\de-de 2008-10-14 16:58 . 2008-10-14 16:58 <DIR> d-------- C:\WINDOWS\system32\de 2008-10-14 16:58 . 2008-10-14 16:58 <DIR> d-------- C:\WINDOWS\system32\bits 2008-10-14 16:58 . 2008-10-14 16:58 <DIR> d-------- C:\WINDOWS\l2schemas 2008-10-14 16:56 . 2008-10-14 16:58 <DIR> d-------- C:\WINDOWS\ServicePackFiles 2008-10-14 16:51 . 2008-10-14 16:51 <DIR> d-------- C:\WINDOWS\EHome 2008-10-14 14:45 . 2004-08-04 00:38 701,952 --------- C:\WINDOWS\system32\drivers\ati2mtag.sys 2008-10-02 20:35 . 2008-10-02 20:35 <DIR> d-------- C:\Dokumente und Einstellungen\Kostja\Anwendungsdaten\DivX 2008-10-02 19:50 . 2008-10-02 19:51 <DIR> d-------- C:\Programme\DivX 2008-09-28 12:15 . 2008-10-01 18:57 <DIR> d-------- C:\Programme\Cheat Engine 2008-09-28 12:15 . 2006-09-04 20:16 1,970,176 --a------ C:\WINDOWS\system32\d3dx9.dll 2008-09-28 12:15 . 2006-09-04 20:16 679,936 --a------ C:\WINDOWS\system32\D3DX81ab.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-10-25 13:10 --------- d-----w C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Kaspersky Lab 2008-10-24 23:06 737,312 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat 2008-10-24 23:06 5,444,128 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat 2008-10-24 23:06 46,756 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx 2008-10-24 23:06 4,648 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx 2008-10-24 10:04 --------- d-----w C:\Programme\ICQToolbar 2008-10-21 08:30 --------- d--h--w C:\Programme\InstallShield Installation Information 2008-10-11 21:49 --------- d-----w C:\Dokumente und Einstellungen\Kostja\Anwendungsdaten\Skype 2008-09-28 19:43 --------- d-----w C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\nView_Profiles 2008-09-27 20:04 --------- d-----w C:\Programme\AutoBINGOOO 2008-09-25 11:55 --------- d-----w C:\Programme\QIP Infium 2008-09-24 18:44 --------- d-----w C:\Dokumente und Einstellungen\Kostja\Anwendungsdaten\QIP 2008-09-22 16:08 --------- d-----w C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Nokia 2008-09-22 15:58 --------- d-----w C:\Programme\Nokia 2008-09-22 15:58 --------- d-----w C:\Programme\MSXML 6.0 2008-09-22 15:57 --------- d-----w C:\Programme\Gemeinsame Dateien\Nokia 2008-09-22 15:57 --------- d-----w C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Installations 2008-09-17 17:58 --------- d-----w C:\Programme\Gemeinsame Dateien\DFX 2008-09-17 17:58 --------- d-----w C:\Programme\DFX 2008-09-17 17:58 --------- d-----w C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\DFX 2008-09-16 00:14 9,464 ------w C:\WINDOWS\system32\drivers\cdralw2k.sys 2008-09-16 00:14 9,336 ------w C:\WINDOWS\system32\drivers\cdr4_xp.sys 2008-09-16 00:14 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe 2008-09-16 00:14 43,528 ------w C:\WINDOWS\system32\drivers\PxHelp20.sys 2008-09-16 00:14 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll 2008-09-16 00:14 129,784 ------w C:\WINDOWS\system32\pxafs.dll 2008-09-16 00:14 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe 2008-09-16 00:14 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe 2008-09-16 00:12 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll 2008-09-16 00:12 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll 2008-09-16 00:12 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll 2008-09-16 00:12 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll 2008-09-16 00:12 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll 2008-09-16 00:12 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll 2008-09-16 00:12 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll 2008-09-16 00:12 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll 2008-09-16 00:12 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll 2008-09-16 00:12 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll 2008-09-16 00:11 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll 2008-09-16 00:11 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll 2008-09-16 00:11 815,104 ----a-w C:\WINDOWS\system32\divx_xx0a.dll 2008-09-16 00:11 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll 2008-09-16 00:11 683,520 ----a-w C:\WINDOWS\system32\DivX.dll 2008-09-16 00:11 161,096 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe 2008-09-16 00:11 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll 2008-09-15 15:24 1,846,528 ----a-w C:\WINDOWS\system32\win32k.sys 2008-09-08 13:51 --------- d-----w C:\Dokumente und Einstellungen\Kostja\Anwendungsdaten\GetRightToGo 2008-09-08 10:41 333,824 ----a-w C:\WINDOWS\system32\drivers\srv.sys 2008-09-07 10:21 --------- d-----w C:\Programme\Gemeinsame Dateien\BioWare 2008-09-07 09:20 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys 2008-09-07 09:19 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe 2008-08-30 10:14 --------- d-----w C:\Dokumente und Einstellungen\Kostja\Anwendungsdaten\ICQ 2008-08-30 08:46 --------- d-----w C:\Programme\QIP 2008-08-27 15:23 96,976 ----a-w C:\WINDOWS\system32\drivers\klin.dat 2008-08-27 15:23 87,855 ----a-w C:\WINDOWS\system32\drivers\klick.dat 2008-08-27 15:12 --------- d-----w C:\Programme\Kaspersky Lab 2008-08-27 15:11 --------- d-----w C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Kaspersky Lab Setup Files 2008-08-25 16:31 --------- d-----w C:\Programme\thriXXX 2008-08-20 05:08 671,744 ----a-w C:\WINDOWS\system32\wininet.dll 2008-08-14 13:19 2,147,840 ----a-w C:\WINDOWS\system32\ntoskrnl.exe 2008-08-14 13:19 2,026,496 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe 2008-06-28 12:47 22,328 ----a-w C:\Dokumente und Einstellungen\Kostja\Anwendungsdaten\PnkBstrK.sys 2007-09-08 16:10 774,144 ----a-w C:\Programme\RngInterstitial.dll 1999-04-29 20:00 99,840 ----a-w C:\Programme\Gemeinsame Dateien\IRAABOUT.DLL 1999-04-29 20:00 70,144 ----a-w C:\Programme\Gemeinsame Dateien\IRAMDMTR.DLL 1999-04-29 20:00 48,640 ----a-w C:\Programme\Gemeinsame Dateien\IRALPTTR.DLL 1999-04-29 20:00 31,744 ----a-w C:\Programme\Gemeinsame Dateien\IRAWEBTR.DLL 1999-04-29 20:00 186,368 ----a-w C:\Programme\Gemeinsame Dateien\IRAREG.DLL 1999-04-29 20:00 17,920 ----a-w C:\Programme\Gemeinsame Dateien\IRASRIAL.DLL . ((((((((((((((((((((((((((((( snapshot@2008-10-24_14.08.37.32 ))))))))))))))))))))))))))))))))))))))))) . - 2008-10-24 11:23:10 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat + 2008-10-25 13:09:57 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat - 2008-10-24 11:23:10 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Lokale Einstellungen\Verlauf\History.IE5\index.dat + 2008-10-25 13:09:57 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Lokale Einstellungen\Verlauf\History.IE5\index.dat + 2008-05-07 05:38:20 17,536 ----a-w C:\WINDOWS\system32\drivers\ccdcmb.sys + 2008-05-07 05:38:20 20,864 ----a-w C:\WINDOWS\system32\drivers\ccdcmbo.sys + 2008-06-06 07:24:44 8,064 ----a-w C:\WINDOWS\system32\drivers\usbser_lowerflt.sys + 2008-05-07 05:38:36 8,064 ----a-w C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys + 2006-11-02 05:22:54 492,000 ------w C:\WINDOWS\system32\drivers\wdf01000.sys + 2006-11-02 05:22:52 32,224 ------w C:\WINDOWS\system32\drivers\wdfldr.sys + 2008-05-07 05:38:34 659,968 ----a-w C:\WINDOWS\system32\nmwcdcocls.dll + 2008-05-07 05:39:22 1,419,232 ----a-w C:\WINDOWS\system32\wdfcoinstaller01005.dll + 2008-10-25 13:09:44 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_750.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{ecdee021-0d17-467f-a1ff-c7a115230949}"= "C:\Programme\free-downloads.net\tbfree.dll" [2007-12-10 1510424] [HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ecdee021-0d17-467f-a1ff-c7a115230949}] 2007-12-10 14:46 1510424 --a------ C:\Programme\free-downloads.net\tbfree.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{ecdee021-0d17-467f-a1ff-c7a115230949}"= "C:\Programme\free-downloads.net\tbfree.dll" [2007-12-10 1510424] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{ECDEE021-0D17-467F-A1FF-C7A115230949}"= "C:\Programme\free-downloads.net\tbfree.dll" [2007-12-10 1510424] [HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMBgMonitor.exe" [2006-07-31 139264] "BitComet"="C:\Programme\BitComet\BitComet.exe" [2007-09-10 6338360] "NVIDIA nTune"="C:\Programme\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-04-04 81920] "AlcoholAutomount"="C:\Programme\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-01-24 4608] "Veoh"="C:\Programme\Veoh Networks\Veoh\VeohClient.exe" [2008-08-28 3660848] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "JMB36X IDE Setup"="C:\WINDOWS\JM\JMInsIDE.exe" [2006-10-30 36864] "36X Raid Configurer"="C:\WINDOWS\system32\JMRaidSetup.exe" [2006-11-16 1953792] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-28 8466432] "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-06-28 81920] "TkBellExe"="C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" [2007-09-08 185632] "CherryKeyMan"="C:\Programme\Cherry\KeyMan\KeyMan.exe" [2006-08-02 237620] "ElbyCheckAnyDVD"="C:\Programme\SlySoft\AnyDVD\ElbyCheck.exe" [2002-11-02 45056] "AsusStartupHelp"="C:\Programme\ASUS\AASP\1.00.15\AsRunHelp.exe" [2006-11-14 363008] "Ai Nap"="C:\Programme\ASUS\AI Nap\AiNap.exe" [2006-11-30 1419776] "DAEMON Tools-1033"="C:\Programme\D-Tools\daemon.exe" [2004-08-22 81920] "SoundMAXPnP"="C:\Programme\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352] "Adobe Reader Speed Launcher"="C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792] "PCSuiteTrayApplication"="C:\Programme\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-06-18 271360] "AnyDVD"="C:\Programme\SlySoft\AnyDVD\AnyDVD.exe" [2003-08-24 210944] "AVP"="C:\Programme\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2008-04-25 201992] "nwiz"="nwiz.exe" [2007-06-28 C:\WINDOWS\system32\nwiz.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360] "Nokia.PCSync"="C:\Programme\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 1241088] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{93994DE8-8239-4655-B1D1-5F4E91300429}"= "C:\PROGRA~1\DVDREG~1\DVDShell.dll" [2004-10-09 49152] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "msacm.l3acm"= l3codecp.acm [HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenu^Programme^Autostart^Adobe Reader - Schnellstart.lnk] path=C:\Dokumente und Einstellungen\All Users\Startmenu\Programme\Autostart\Adobe Reader - Schnellstart.lnk backup=C:\WINDOWS\pss\Adobe Reader - Schnellstart.lnkCommon Startup [HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenu^Programme^Autostart^Adobe Reader Synchronizer.lnk] path=C:\Dokumente und Einstellungen\All Users\Startmenu\Programme\Autostart\Adobe Reader Synchronizer.lnk backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup [HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenu^Programme^Autostart^Microsoft Office.lnk] path=C:\Dokumente und Einstellungen\All Users\Startmenu\Programme\Autostart\Microsoft Office.lnk backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup [HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenu^Programme^Autostart^ScanPanel.lnk] path=C:\Dokumente und Einstellungen\All Users\Startmenu\Programme\Autostart\ScanPanel.lnk backup=C:\WINDOWS\pss\ScanPanel.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Easy-PrintToolBox] --a------ 2004-01-14 03:10 409600 C:\Programme\Canon\Easy-PrintToolBox\BJPSMAIN.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] --------- 2008-04-14 04:22 1695232 C:\Programme\Messenger\msmsgs.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] --a------ 2006-01-12 16:40 155648 C:\Programme\Gemeinsame Dateien\Ahead\Lib\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl] --a------ 2003-12-08 17:35 32768 C:\Programme\CyberLink\PowerDVD\PDVDServ.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] -ra------ 2007-08-31 17:40 22879528 C:\Programme\Skype\Phone\Skype.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "PnkBstrA"=2 (0x2) "LightScribeService"=2 (0x2) [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Programme\\Gemeinsame Dateien\\Ahead\\Nero Web\\SetupX.exe"= "C:\\Programme\\BitComet\\BitComet.exe"= "C:\\Programme\\EA GAMES\\Battlefield 2\\BF2.exe"= "C:\\Programme\\Xpage Internet Studio 6 Special Edition\\jre\\bin\\javaw.exe"= "C:\\Programme\\THQ\\Titan Quest\\Titan Quest.exe"= "C:\\Programme\\Nero\\Nero Sipps\\Phone.exe"= "C:\\Programme\\Microsoft Games\\Age of Empires III\\age3x.exe"= "C:\\WINDOWS\\system32\\dpnsvr.exe"= "C:\\Programme\\Battlestations Midway\\Battlestationsmidway.exe"= "C:\\Programme\\Battlefield 2142\\BF2142.exe"= "C:\\Programme\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"= "C:\\Programme\\Veoh Networks\\Veoh\\VeohClient.exe"= "C:\\Programme\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx9.exe"= "C:\\Programme\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx10.exe"= "C:\\Programme\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Launcher.exe"= "C:\\Programme\\Microsoft Games\\Age of Empires III\\age3y.exe"= "C:\\WINDOWS\\system32\\PnkBstrA.exe"= "C:\\WINDOWS\\system32\\PnkBstrB.exe"= "C:\\Programme\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"= "D:\\mass ef.game\\Mass Effect\\Binaries\\MassEffect.exe"= "D:\\mass ef.game\\Mass Effect\\MassEffectLauncher.exe"= "C:\\Programme\\Skype\\Phone\\Skype.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "23496:TCP"= 23496:TCP:BitComet 23496 TCP "23496:UDP"= 23496:UDP:BitComet 23496 UDP R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [2008-01-29 32784] R0 sfdrv02;FrontLine Environment Driver (v2);C:\WINDOWS\system32\drivers\sfdrv02.sys [2006-09-11 67960] R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);C:\WINDOWS\system32\drivers\sfsync03.sys [2005-10-13 35328] R0 sfsync05;FrontLine Synchronization Driver (v5);C:\WINDOWS\system32\drivers\sfsync05.sys [2006-08-11 59776] R2 PStrip;PStrip;C:\WINDOWS\system32\drivers\pstrip.sys [2007-07-15 27992] R3 Ch2kUSB;Cherry USB Treiber fьr CDI;C:\WINDOWS\system32\drivers\Ch2kUSB.sys [2006-06-29 167566] R3 Ch2kUSBM;Cherry USB Maus Treiber fьr CDI;C:\WINDOWS\system32\drivers\Ch2kUSBm.sys [2006-04-28 72149] R3 Cherry Device Interface;Cherry Device Interface;C:\Programme\Cherry\CDI\cdi.exe [2006-06-27 573486] R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2008-03-25 24592] S2 sfrem02;FrontLine Drivers Auto Removal (v2);C:\WINDOWS\system32\sfrem02.exe svc [ ] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8243dcc3-5c8a-11dc-92f4-806d6172696f}] \Shell\AutoRun\command - H:\Autorun.exe . . ------- Supplementary Scan ------- . FireFox -: Profile - C:\Dokumente und Einstellungen\Kostja\Anwendungsdaten\Mozilla\Firefox\Profiles\nr2gosvq.default\ FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q= FF -: plugin - C:\Programme\Mozilla Firefox\plugins\npgcplug.dll FF -: plugin - C:\Programme\Mozilla Firefox\plugins\npracplug.dll FF -: plugin - C:\Programme\Real\RealArcade\Plugins\Mozilla\npracplug.dll FF -: plugin - C:\Programme\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-10-25 15:24:14 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... ************************************************************************** . Completion time: 2008-10-25 15:25:59 ComboFix-quarantined-files.txt 2008-10-25 13:24:57 ComboFix2.txt 2008-10-24 12:08:54 Pre-Run: 17 Verzeichnis(se), 36.027.789.312 Bytes frei Post-Run: 17 Verzeichnis(se), 36,012,658,688 Bytes frei 280 --- E O F --- 2008-10-24 09:18:22 |
|
|
||
25.10.2008, 19:59
Member
Beiträge: 3716 |
#4
bitte auch den rest posten
|
|
|
||
26.10.2008, 18:24
...neu hier
Themenstarter Beiträge: 3 |
#5
sorry hab erst jetst verstanden was du meinst
Verzeichnis von c:\ 26.10.2008 18:18 0 dirdat.txt 26.10.2008 11:47 2.145.386.496 pagefile.sys 25.10.2008 14:26 20.694 ComboFix.txt 14.10.2008 15:55 251.712 ntldr 23.08.2008 13:03 0 nowy.avi 02.03.2008 20:11 223 boot.ini 06.09.2007 15:14 0 MSDOS.SYS 06.09.2007 15:14 0 CONFIG.SYS 06.09.2007 15:14 0 IO.SYS 06.09.2007 15:14 0 AUTOEXEC.BAT 04.08.2004 13:00 4.952 bootfont.bin 04.08.2004 13:00 47.564 NTDETECT.COM 12 Datei(en) 2.145.711.641 Bytes 0 Verzeichnis(se), 36.020.883.456 Bytes frei Datentrager in Laufwerk C: ist System Volumeseriennummer: 50FE-3C86 Verzeichnis von C:\WINDOWS\system32 24.10.2008 23:07 13.668 wpa.dbl 15.10.2008 17:35 337.408 netapi32.dll 15.10.2008 15:46 187.408 FNTCACHE.DAT 14.10.2008 16:11 397.696 perfh009.dat 14.10.2008 16:11 59.916 perfc009.dat 14.10.2008 16:11 411.362 perfh007.dat 14.10.2008 16:11 72.622 perfc007.dat 14.10.2008 16:11 952.938 PerfStringBackup.INI 14.10.2008 16:09 253 spupdwxp.log 14.10.2008 15:43 3.284 ANIWZCS{E2D825CF-6235-413F-B49B-3B61E41FAC5F} 07.10.2008 20:19 16.721.856 MRT.exe 16.09.2008 01:14 10.152 dsm_de.qm 16.09.2008 01:14 4.816 divxsm.tlb 16.09.2008 01:14 524.288 DivXsm.exe 16.09.2008 01:14 3.596.288 qt-dx331.dll 16.09.2008 01:14 187.128 pxmas.dll 16.09.2008 01:14 379.640 pxwave.dll 16.09.2008 01:14 72.440 pxhpinst.exe 16.09.2008 01:14 1.628.920 pxsfs.dll 16.09.2008 01:14 64.760 pxinsa64.exe 16.09.2008 01:14 88.824 vxblock.dll 16.09.2008 01:14 551.672 px.dll 16.09.2008 01:14 118.520 pxinsi64.exe 16.09.2008 01:14 518.904 pxdrv.dll 16.09.2008 01:14 120.056 pxcpyi64.exe 16.09.2008 01:14 66.296 pxcpya64.exe 16.09.2008 01:14 129.784 pxafs.dll 16.09.2008 01:12 200.704 ssldivx.dll 16.09.2008 01:12 1.044.480 libdivx.dll 16.09.2008 01:12 416 dpl100.dll.manifest 16.09.2008 01:12 81.920 dpl100.dll 16.09.2008 01:12 3.051 dtu_de.qm 16.09.2008 01:12 196.608 dtu100.dll 16.09.2008 01:12 416 dtu100.dll.manifest 16.09.2008 01:12 593.920 dpuGUI11.dll 16.09.2008 01:12 294.912 dpu10.dll 16.09.2008 01:12 344.064 dpus11.dll 16.09.2008 01:12 57.344 dpv11.dll 16.09.2008 01:12 53.248 dpuGUI10.dll 16.09.2008 01:12 8.523 dpude.qm 16.09.2008 01:12 294.912 dpu11.dll 16.09.2008 01:11 815.104 divx_xx0a.dll 16.09.2008 01:11 823.296 divx_xx07.dll 16.09.2008 01:11 802.816 divx_xx11.dll 16.09.2008 01:11 823.296 divx_xx0c.dll 16.09.2008 01:11 683.520 DivX.dll 16.09.2008 01:11 634.880 divxdec.ax 16.09.2008 01:11 352.401 DivXMedia.ax 16.09.2008 01:11 161.096 DivXCodecVersionChecker.exe 16.09.2008 01:11 12.288 DivXWMPExtType.dll 15.09.2008 16:24 1.846.528 win32k.sys 12.09.2008 13:56 128.575 nvapps.xml 07.09.2008 10:19 107.832 PnkBstrB.exe 27.08.2008 16:27 487.388 TZLog.log 20.08.2008 06:08 3.088.896 mshtml.dll 20.08.2008 06:08 671.744 wininet.dll 20.08.2008 06:08 620.544 urlmon.dll 20.08.2008 06:08 1.499.136 shdocvw.dll 14.08.2008 14:19 2.026.496 ntkrnlpa.exe 14.08.2008 14:19 2.147.840 ntoskrnl.exe 18.07.2008 21:10 94.920 cdm.dll 18.07.2008 21:10 53.448 wuauclt.exe 18.07.2008 21:10 45.768 wups2.dll 18.07.2008 21:10 36.552 wups.dll 18.07.2008 21:10 33.992 wucltui.dll.mui 18.07.2008 21:09 29.896 wuaucpl.cpl.mui 18.07.2008 21:09 29.896 wuapi.dll.mui 18.07.2008 21:09 325.832 wucltui.dll 18.07.2008 21:09 215.752 wuaucpl.cpl 18.07.2008 21:09 563.912 wuapi.dll 18.07.2008 21:09 205.000 wuweb.dll 18.07.2008 21:09 1.811.656 wuaueng.dll 18.07.2008 21:08 21.192 wuaueng.dll.mui 07.07.2008 21:26 253.952 es.dll 28.06.2008 13:49 66.872 PnkBstrA.exe 24.06.2008 17:42 74.240 mscms.dll 24.06.2008 17:12 295.936 wmpeffects.dll 20.06.2008 18:46 147.968 dnsapi.dll 20.06.2008 18:46 247.296 mswsock.dll 10.05.2008 00:24 135.168 wshom.ocx 09.05.2008 11:54 90.112 wshext.dll 09.05.2008 11:54 180.224 scrobj.dll 09.05.2008 11:54 430.080 vbscript.dll 09.05.2008 11:54 172.032 scrrun.dll 09.05.2008 11:54 512.000 jscript.dll 08.05.2008 12:24 155.648 wscript.exe 07.05.2008 10:07 135.168 cscript.exe 07.05.2008 06:39 1.419.232 wdfcoinstaller01005.dll 07.05.2008 06:38 659.968 nmwcdcocls.dll 07.05.2008 06:38 90.624 nmwcdcls.dll 07.05.2008 06:10 1.293.824 quartz.dll 2256 Datei(en) 604.471.482 Bytes 0 Verzeichnis(se), 36.020.756.480 Bytes frei Datentrager in Laufwerk C: ist System Volumeseriennummer: 50FE-3C86 Verzeichnis von C:\WINDOWS 26.10.2008 18:18 39.032 setupapi.log 26.10.2008 18:04 1.122.143 WindowsUpdate.log 26.10.2008 18:04 1.596 wmsetup.log 26.10.2008 15:34 116 NeroDigital.ini 26.10.2008 11:47 0 0.log 26.10.2008 11:47 159 wiadebug.log 26.10.2008 11:47 50 wiaservc.log 26.10.2008 11:47 2.048 bootstat.dat 26.10.2008 00:26 32.588 SchedLgU.Txt 25.10.2008 18:08 67 DVDRegionFree.INI 25.10.2008 14:24 227 system.ini 24.10.2008 23:10 413 setupact.log 24.10.2008 23:10 968 iis6.log 24.10.2008 23:10 2.061 comsetup.log 24.10.2008 23:10 1.247 ntdtcsetup.log 24.10.2008 23:10 2.359 tsoc.log 24.10.2008 23:10 1.393 imsins.log 24.10.2008 23:10 8.434 Wdf01005Inst.log 24.10.2008 23:10 342 ocmsn.log 24.10.2008 23:10 2.956 ocgen.log 24.10.2008 23:10 309 msgsocm.log 24.10.2008 23:10 6.184 FaxSetup.log 24.10.2008 23:09 0 setuperr.log 23.10.2008 22:02 639 win.ini 14.10.2008 16:24 33.860 Ascd_tmp.ini 14.10.2008 16:12 374 capture.ini 06.09.2008 16:12 1.080 gramit32.cfg 11.07.2008 13:42 151 PhotoSnapViewer.INI 28.06.2008 13:47 311 game.ini 25.05.2008 16:42 122 mdm.ini 20.05.2008 21:16 99 abreg.ini 14.04.2008 03:23 288.768 winhlp32.exe 14.04.2008 03:23 32.866 slrundll.exe 14.04.2008 03:22 153.600 regedit.exe 14.04.2008 03:22 70.144 notepad.exe 14.04.2008 03:22 10.752 hh.exe 14.04.2008 03:22 1.036.800 explorer.exe 14.04.2008 03:22 50.688 twain_32.dll 10.02.2008 18:09 1.043.070 setupapi.log.1.old 30.01.2008 13:49 1.261 mozver.dat 13.01.2008 19:04 11.479 Dusb4ar.ini 06.01.2008 20:23 1.289 ScnPanel.ini 08.11.2007 23:09 2.677 Ausba4.ini 10.10.2007 19:25 1.024.956 setupapi.log.0.old 07.10.2007 18:40 316.640 WMSysPr9.prx 07.10.2007 13:05 0 AS_Debug.txt 04.10.2007 21:59 33 6816BadPixelInfo.txt 04.10.2007 21:59 4 6816Error.dat 04.10.2007 21:59 30.720 6816White12.dat 04.10.2007 21:58 30.720 6816Dark12.dat 04.10.2007 21:58 6 6816Exposure.dat 04.10.2007 21:58 3 6816Offset.dat 04.10.2007 21:58 3 6816Gain.dat 01.10.2007 09:07 229.057 Alcohol_Toolbar_Uninstaller_4765.exe 11.09.2007 17:28 0 OpPrintServer.INI 08.09.2007 17:27 403 ODBC.INI 08.09.2007 11:24 0 nsreg.dat 06.09.2007 16:16 0 NSREX.INI 06.09.2007 16:16 59 vbaddin.ini 06.09.2007 16:09 0 Sti_Trace.log 06.09.2007 15:16 8.192 REGLOCS.OLD 06.09.2007 15:14 0 control.ini 06.09.2007 15:14 4.161 ODBCINST.INI 06.09.2007 15:14 749 WindowsShell.Manifest 06.09.2007 15:12 36 vb.ini 04.04.2007 13:21 6.912 nvoclock.sys 04.04.2007 13:20 393.216 ntuneoem.dll 04.04.2007 13:20 1.622.016 NVBenchMarks.dll 04.04.2007 13:19 28.672 AutoTuneScript.dll 12.03.2007 11:01 217.088 NVGfxOgl.dll 28.12.2006 20:01 19.569 002745_.tmp 31.07.2006 12:34 78.027 UNNeroSipps.cfg 28.07.2006 17:11 3.076.096 UNNeroSipps.exe 14.07.2006 16:29 966.656 UNRecode.exe 14.07.2006 16:29 966.656 UNNeroVision.exe 14.07.2006 16:29 966.656 UNNeroBackItUp.exe 14.07.2006 16:29 966.656 UNNeroMediaHome.exe 14.07.2006 16:29 966.656 UNNeroShowTime.exe 129 Datei(en) 20.980.265 Bytes 0 Verzeichnis(se), 36.020.768.768 Bytes frei Datentrager in Laufwerk C: ist System Volumeseriennummer: 50FE-3C86 Verzeichnis von C:\DOKUME~1\Kostja\LOKALE~1\Temp 26.10.2008 18:08 181 TMP52.ini 26.10.2008 18:08 0 TMP52.tmp 26.10.2008 17:57 0 TMP4D.tmp 26.10.2008 17:57 0 TMP4C.tmp 26.10.2008 17:57 181 TMP4C.ini 26.10.2008 11:48 16.384 Perflib_Perfdata_ab8.dat 26.10.2008 11:48 16.384 ~DF8F24.tmp 25.10.2008 14:10 16.384 ~DF9074.tmp 8 Datei(en) 49.514 Bytes 0 Verzeichnis(se), 36.020.768.768 Bytes frei |
|
|
||
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:33:40, on 24.10.2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Programme\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe
C:\Programme\Cherry\KeyMan\KeyMan.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programme\ASUS\AI Nap\AiNap.exe
C:\Programme\D-Tools\daemon.exe
C:\Programme\Analog Devices\Core\smax4pnp.exe
C:\Programme\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Programme\Cherry\CDI\cdi.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMBgMonitor.exe
C:\Programme\PC Connectivity Solution\ServiceLayer.exe
C:\Programme\Veoh Networks\Veoh\VeohClient.exe
C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\explorer.exe
C:\Programme\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Programme\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Programme\Mozilla Firefox\firefox.exe
C:\Programme\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Programme\free-downloads.net\tbfree.dll
O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Programme\BitComet\tools\BitCometBHO_1.1.8.30.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Programme\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: Alcohol Toolbar Helper - {8126A4A5-BFD3-46FE-BBDF-BFB5CF78E489} - C:\Programme\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll
O2 - BHO: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Programme\free-downloads.net\tbfree.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Programme\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Alcohol Toolbar - {ED4BD629-C1B6-4399-8A34-02CCAA921DC9} - C:\Programme\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll
O3 - Toolbar: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Programme\free-downloads.net\tbfree.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Programme\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\JMRaidSetup.exe boot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TkBellExe] "C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [CherryKeyMan] "C:\Programme\Cherry\KeyMan\KeyMan.exe"
O4 - HKLM\..\Run: [ElbyCheckAnyDVD] "C:\Programme\SlySoft\AnyDVD\ElbyCheck.exe" /L AnyDVD
O4 - HKLM\..\Run: [AsusStartupHelp] C:\Programme\ASUS\AASP\1.00.15\AsRunHelp.exe
O4 - HKLM\..\Run: [Ai Nap] "C:\Programme\ASUS\AI Nap\AiNap.exe"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programme\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programme\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programme\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [AnyDVD] C:\Programme\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [AVP] "C:\Programme\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [BitComet] "C:\Programme\BitComet\BitComet.exe" /tray
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Programme\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Programme\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [Veoh] "C:\Programme\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Programme\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Programme\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Programme\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: Coaoenoeea caueou aaa-o?aoeea - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Programme\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Programme\BitComet\tools\BitCometBHO_1.1.8.30.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Programme\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: Cherry Device Interface - Cherry, Auerbach Germany, www.cherry.de - C:\Programme\Cherry\CDI\cdi.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - C:\Programme\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Programme\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programme\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: FrontLine Drivers Auto Removal (v2) (sfrem02) - Protection Technology (StarForce) - C:\WINDOWS\system32\sfrem02.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Programme\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
--
End of file - 8354 bytes
ich danke euch schon mal im vorraus.