Here's My Final Results...Pls. Analyse...Thanks In Advance... ========================
ComboFix Log:
========================ComboFix 10-05-06.05 - princeedward 07.05.2010 16:34:33.6.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.49.1031.18.511.243 [GMT 2:00]
ausgeführt von:: c:\dokumente und einstellungen\princeedward\Desktop\ComboFix.exe
Benutzte Befehlsschalter :: c:\dokumente und einstellungen\princeedward\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1368 [VPS 100504-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: BitDefender Antivirus *On-access scanning disabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: BitDefender Firewall *disabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
FILE ::
"c:\windows\system32\ \SVZHOST.exe"
.
((((((((((((((((((((((( Dateien erstellt von 2010-04-07 bis 2010-05-07 ))))))))))))))))))))))))))))))
.
2010-05-06 04:19 . 2009-11-21 15:54 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-05-06 04:14 . 2009-10-23 15:28 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2010-05-06 04:11 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-05-04 17:02 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-05-04 17:02 . 2010-05-04 17:03 -------- d-----w- c:\programme\Malwarebytes' Anti-Malware
2010-05-04 15:39 . 2010-05-04 15:39 -------- d-----w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\Malwarebytes
2010-05-04 15:39 . 2010-05-04 15:39 -------- d-----w- c:\dokumente und einstellungen\princeedward\Anwendungsdaten\Malwarebytes
2010-05-04 15:33 . 2010-05-04 15:34 -------- d-----w- c:\dokumente und einstellungen\princeedward\Anwendungsdaten\ArcSoft
2010-05-04 12:05 . 2010-05-04 12:05 -------- d-----w- c:\dokumente und einstellungen\princeedward\Anwendungsdaten\Malwarebytes-BackupByMalwarebytesPortable
2010-05-04 12:04 . 2010-05-04 12:04 -------- d-----w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\Malwarebytes-BackupByMalwarebytesPortable
2010-05-02 05:28 . 2010-05-02 05:28 -------- d-----w- c:\dokumente und einstellungen\princeedward\Anwendungsdaten\TuneUp Software
2010-05-02 05:28 . 2010-05-05 17:30 -------- d-----w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\TuneUp Software
2010-04-30 19:01 . 2010-04-30 19:01 -------- d-----w- c:\programme\Trend Micro
2010-04-30 16:56 . 2010-04-30 17:33 -------- d-----w- c:\programme\NoAdware5.0
2010-04-30 15:21 . 2002-10-01 07:22 9856 ------w- c:\windows\system32\drivers\pfc.sys
2010-04-30 15:21 . 2010-04-30 15:21 -------- d-----w- c:\programme\ArcSoft
2010-04-30 15:21 . 1999-05-26 07:46 212480 ----a-w- c:\windows\pcdlib32.dll
2010-04-30 15:04 . 2010-04-30 15:17 -------- d-----w- c:\programme\Canon
2010-04-30 07:22 . 2010-04-30 07:22 -------- d-----r- c:\dokumente und einstellungen\NetworkService\Favoriten
2010-04-29 12:14 . 2010-04-29 12:14 -------- d-----w- c:\dokumente und einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Adobe
2010-04-29 10:19 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 08:00 . 2010-04-29 08:00 -------- d-----w- c:\dokumente und einstellungen\princeedward\Lokale Einstellungen\Anwendungsdaten\Threat Expert
2010-04-27 18:52 . 2010-01-22 07:55 767952 ----a-w- c:\windows\BDTSupport.dll
2010-04-27 18:52 . 2010-01-22 07:56 149456 ----a-w- c:\windows\SGDetectionTool.dll
2010-04-27 18:52 . 2008-11-26 10:08 131 ----a-w- c:\windows\IDB.zip
2010-04-27 18:52 . 2010-01-22 07:56 165840 ----a-w- c:\windows\PCTBDRes.dll
2010-04-27 18:52 . 2010-01-22 07:56 1652688 ----a-w- c:\windows\PCTBDCore.dll
2010-04-27 18:52 . 2009-10-27 23:36 1152444 ----a-w- c:\windows\UDB.zip
2010-04-27 18:48 . 2010-02-05 07:17 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2010-04-27 18:47 . 2010-03-29 08:06 218592 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2010-04-27 18:47 . 2009-11-23 11:54 88040 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2010-04-27 18:47 . 2010-04-08 12:29 63360 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2010-04-27 18:47 . 2010-04-30 08:14 -------- d-----w- c:\programme\Spyware Doctor
2010-04-27 18:47 . 2010-04-27 18:54 -------- d-----w- c:\programme\Gemeinsame Dateien\PC Tools
2010-04-27 18:47 . 2010-04-27 18:47 -------- d-----w- c:\dokumente und einstellungen\princeedward\Anwendungsdaten\PC Tools
2010-04-27 18:47 . 2010-04-27 18:47 -------- d-----w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\PC Tools
2010-04-27 16:28 . 2010-05-07 14:25 -------- d---a-w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\TEMP
2010-04-27 16:05 . 2010-05-02 06:30 -------- d-----w- c:\programme\Panda Security
2010-04-27 14:41 . 2010-04-27 14:41 -------- d-----w- c:\windows\McAfee.com
2010-04-27 13:53 . 2009-08-06 17:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-04-27 13:53 . 2009-08-06 17:23 215920 ----a-w- c:\windows\system32\muweb.dll
2010-04-27 04:13 . 2010-04-27 04:22 -------- d-----w- c:\programme\MSECache
2010-04-26 21:08 . 2010-04-27 04:28 -------- d-----w- c:\dokumente und einstellungen\princeedward\Anwendungsdaten\GetRightToGo
2010-04-25 18:10 . 2010-04-25 18:37 -------- d-----w- c:\dokumente und einstellungen\princeedward\Anwendungsdaten\Uniblue
2010-04-25 18:09 . 2010-04-25 18:36 -------- d-----w- c:\programme\Uniblue
2010-04-25 14:41 . 2010-04-25 14:41 -------- d-sh--w- c:\dokumente und einstellungen\NetworkService\IETldCache
2010-04-25 14:33 . 2010-04-25 14:33 -------- d-----w- c:\dokumente und einstellungen\princeedward\Lokale Einstellungen\Anwendungsdaten\MPBMRHPR
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-07 13:54 . 2009-08-09 08:43 -------- d-----w- c:\dokumente und einstellungen\princeedward\Anwendungsdaten\Skype
2010-05-07 13:53 . 2009-08-09 08:44 -------- d-----w- c:\dokumente und einstellungen\princeedward\Anwendungsdaten\skypePM
2010-05-06 15:11 . 2009-11-28 09:16 -------- d-----w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\Spybot - Search & Destroy
2010-05-06 04:38 . 2002-08-29 12:00 84326 ----a-w- c:\windows\system32\perfc007.dat
2010-05-06 04:38 . 2002-08-29 12:00 458822 ----a-w- c:\windows\system32\perfh007.dat
2010-05-02 06:28 . 2009-08-09 15:40 -------- d-----w- c:\programme\CursorXP
2010-04-30 15:21 . 2009-08-07 18:13 -------- d--h--w- c:\programme\InstallShield Installation Information
2010-04-29 10:19 . 2010-04-29 10:19 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys.bak
2010-04-28 16:01 . 2009-08-07 17:20 81376 ----a-w- c:\dokumente und einstellungen\princeedward\Lokale Einstellungen\Anwendungsdaten\GDIPFONTCACHEV1.DAT
2010-04-25 18:33 . 2010-04-25 18:33 4004960 ----a-w- c:\dokumente und einstellungen\princeedward\Anwendungsdaten\Uniblue\RegistryBooster 2010\_temp\ub.exe
2010-04-25 17:02 . 2009-11-28 09:16 -------- d-----w- c:\programme\Spybot - Search & Destroy
2010-04-17 16:10 . 2010-04-05 20:04 1254 ----a-w- c:\dokumente und einstellungen\princeedward\Anwendungsdaten\settings.dat
2010-04-05 06:17 . 2010-04-04 09:25 -------- d-----w- c:\dokumente und einstellungen\princeedward\Anwendungsdaten\Orbit
2010-04-04 17:20 . 2009-08-08 09:13 256 ----a-w- c:\windows\system32\pool.bin
2010-04-04 11:11 . 2010-04-04 11:11 -------- d-----w- c:\dokumente und einstellungen\princeedward\Anwendungsdaten\AVS4YOU
2010-04-04 11:11 . 2010-04-04 11:11 -------- d-----w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\AVS4YOU
2010-04-04 11:10 . 2010-04-04 11:08 -------- d-----w- c:\programme\AVS4YOU
2010-04-04 11:10 . 2010-04-04 11:08 -------- d-----w- c:\programme\Gemeinsame Dateien\AVSMedia
2010-04-04 10:24 . 2009-11-05 22:07 -------- d-----w- c:\dokumente und einstellungen\princeedward\Anwendungsdaten\HandBrake
2010-04-04 10:23 . 2009-11-05 22:00 -------- d-----w- c:\programme\HandBrake
2010-04-04 09:32 . 2010-04-04 09:32 -------- d-----w- c:\dokumente und einstellungen\princeedward\Anwendungsdaten\GrabPro
2010-04-04 09:20 . 2010-04-04 09:20 -------- d-----w- c:\programme\FLV Player
2010-04-03 13:53 . 2009-08-15 10:00 -------- d-----w- c:\dokumente und einstellungen\princeedward\Anwendungsdaten\VSO
2010-04-01 17:25 . 2010-04-01 17:25 53248 ----a-w- c:\dokumente und einstellungen\princeedward\Anwendungsdaten\Thinstall\Microsoft Office Enterprise 2007\1000000b00002h\verclsid.exe
2010-04-01 16:23 . 2010-04-01 16:23 53248 ----a-w- c:\dokumente und einstellungen\princeedward\Anwendungsdaten\Thinstall\Microsoft Office Enterprise 2007\4000006200002h\HPZSTC09.exe
2010-03-26 16:21 . 2010-03-26 16:21 -------- d-----w- c:\programme\Microsoft Silverlight
2010-03-17 18:05 . 2010-03-17 18:05 -------- d-----w- c:\programme\Voobys
2010-03-17 17:24 . 2010-03-17 17:24 -------- d-----w- c:\dokumente und einstellungen\LocalService\Anwendungsdaten\DivX
2010-03-10 06:15 . 2002-08-29 12:00 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-02-25 06:15 . 2002-08-29 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2002-08-29 12:00 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-18 09:38 . 2010-02-18 09:38 520192 ----a-w- c:\windows\system32\Side 9 Screensaver.scr
2010-02-17 12:04 . 2002-08-29 12:00 2192256 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 19:04 . 2002-08-29 03:41 2069120 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 04:33 . 2002-08-29 12:00 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2002-08-29 12:00 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
2009-03-05 16:08 . 2009-09-04 08:14 49664 ----a-w- c:\programme\mozilla firefox\components\FFComm.dll
.
(((((((((((((((((((((((((((((
SnapShot@2010-05-06_15.04.38 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-05-07 14:25 . 2010-05-07 14:25 16384 c:\windows\Temp\Perflib_Perfdata_694.dat
+ 2010-05-07 14:25 . 2010-05-07 14:25 16384 c:\windows\Temp\Perflib_Perfdata_55c.dat
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SkinClock"="c:\programme\Atomic Alarm Clock\AtomicAlarmClock.exe" [2008-07-27 528896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\dokumente und einstellungen\princeedward\Startmen\Programme\Autostart\
Mozilla.lnk - c:\programme\Mozilla Firefox\firefox.exe [2010-2-14 910296]
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^HP Digital Imaging Monitor.lnk]
path=c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Logitech Desktop Messenger.lnk]
path=c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Voobys.lnk]
path=c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\Voobys.lnk
backup=c:\windows\pss\Voobys.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-03-24 18:17 952768 ----a-w- c:\programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-04-04 05:42 36272 ----a-w- c:\programme\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater6]
2009-01-08 06:36 2521464 ----a-w- c:\programme\Gemeinsame Dateien\Adobe\Updater6\Adobe_Updater.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Auto Run Software for Photo Frame]
2008-07-24 13:55 5152256 ----a-w- c:\programme\Philips\Philips PhotoFrame\PhotoManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlackBerryAutoUpdate]
2009-11-19 21:29 623960 ----a-w- c:\programme\Gemeinsame Dateien\Research In Motion\Auto Update\RIMAutoUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 02:22 15360 ----a-w- c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2003-06-25 09:24 49152 ----a-w- c:\programme\HP\HP Software Update\hpwuSchd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPpromo psc 1300 series]
2003-10-09 10:17 126976 ----a-w- c:\programme\HP\Digital Imaging\Promotions\HPpromo.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
2009-09-03 06:24 3114416 ----a-w- c:\programme\Internet Download Manager\IDMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
2004-08-03 20:32 208952 ----a-w- c:\windows\ime\imjp8_1\imjpmig.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint]
2008-06-10 19:56 1406024 ----a-w- c:\programme\Microsoft IntelliPoint\ipoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]
2008-10-24 07:14 206112 ----a-w- c:\programme\Gemeinsame Dateien\InstallShield\UpdateService\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
2009-08-07 19:36 16384 ----a-w- c:\programme\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
2003-08-29 12:17 188416 ----a-w- c:\programme\Logitech\Video\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
2003-08-29 12:20 77824 ----a-w- c:\programme\Logitech\Video\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 15:44 3883856 ----a-w- c:\programme\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
2004-08-03 20:31 59392 ----a-w- c:\windows\system32\IME\PINTLGNT\IMSCINST.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
2004-08-03 20:32 455168 ----a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
2004-08-03 20:32 455168 ----a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-05-26 15:18 413696 ----a-w- c:\programme\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
2009-07-08 11:31 236016 ----a-w- c:\programme\Gemeinsame Dateien\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkinClock]
2008-07-27 12:26 528896 ----a-w- c:\programme\Atomic Alarm Clock\AtomicAlarmClock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2009-07-16 11:20 25604904 ----a-r- c:\programme\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2005-03-24 20:20 77824 ----a-w- c:\windows\SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 15:07 2260480 ------w- c:\programme\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartServiceMPBMRHPR]
2010-04-25 14:33 471040 ----a-w- c:\dokumente und einstellungen\princeedward\Lokale Einstellungen\Anwendungsdaten\MPBMRHPR\StartService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-10-11 03:17 149280 ----a-w- c:\programme\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\zBrowser Launcher]
2002-11-23 00:15 631362 ----a-w- c:\programme\Logitech\iTouch\iTouch.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"MSConfig"=c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
"SVZHOST"=c:\windows\system32\ \SVZHOST.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programme\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programme\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Programme\\Alwil Software\\Avast4\\ashDisp.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Programme\\Mozilla Firefox\\firefox.exe"=
"c:\\Programme\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programme\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programme\\Skype\\Phone\\Skype.exe"=
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [27.04.2010 20:47 218592]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [16.10.2009 17:16 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [16.10.2009 17:16 20560]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\programme\Spyware Doctor\BDT\BDTUpdateService.exe [27.04.2010 20:52 112592]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [04.05.2010 19:02 20952]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [27.10.2009 17:14 717296]
S2 MBAMService;MBAMService;c:\malwarebytesportable\App\Malwarebytes\mbamservice.exe --> c:\malwarebytesportable\App\Malwarebytes\mbamservice.exe [?]
S3 sdAuxService;PC Tools Auxiliary Service;c:\programme\Spyware Doctor\pctsAuxs.exe [27.04.2010 20:47 366840]
.
Inhalt des "geplante Tasks" Ordners
2010-05-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programme\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2010-05-06 c:\windows\Tasks\User_Feed_Synchronization-{AEB630E7-484D-4686-9774-8673BD49534C}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 02:31]
.
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = \blank.htm
uStart Page =
hxxp://facebook.com/uInternet Settings,ProxyOverride = localhost
IE: Download all links with IDM - c:\programme\Internet Download Manager\IEGetAll.htm
IE: Download aller Links mit IDM
IE: Download FLV video content with IDM - c:\programme\Internet Download Manager\IEGetVL.htm
IE: Download FLV-Videoinhalt mit IDM
IE: Download mit IDM
IE: Download with IDM - c:\programme\Internet Download Manager\IEExt.htm
DPF: DirectAnimation Java Classes -
file://c:\windows\Java\classes\dajava.cabDPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cabFF - ProfilePath - c:\dokumente und einstellungen\princeedward\Anwendungsdaten\Mozilla\Firefox\Profiles\8jcdab9i.default\
FF - prefs.js: browser.startup.homepage -
hxxp://google.comFF - plugin: c:\programme\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\programme\Gemeinsame Dateien\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX Richtlinien ----
FF - user.js: network.http.max-connections-per-server - 6
FF - user.js: network.http.max-persistent-connections-per-server - 3
c:\programme\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\programme\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\programme\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\programme\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\programme\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\programme\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\programme\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\programme\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\programme\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\programme\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\programme\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\programme\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\programme\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\programme\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\programme\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\programme\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\programme\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\programme\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\programme\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\programme\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\programme\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\programme\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\programme\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\programme\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\programme\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\programme\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\programme\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\programme\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\programme\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\programme\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\programme\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\programme\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\programme\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\programme\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\programme\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\programme\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-05-07 16:46
Windows 5.1.2600 Service Pack 3 NTFS
Scanne versteckte Prozesse...
Scanne versteckte Autostarteinträge...
Scanne versteckte Dateien...
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{b1267490-c0a8-43ac-89dd-8d81e210ceb1}]
@Denied: (Full) (Everyone)
"Model"=dword:0000002c
"Therad"=dword:0000000c
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
- - - - - - - > 'explorer.exe'(1756)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Zeit der Fertigstellung: 2010-05-07 16:52:50
ComboFix-quarantined-files.txt 2010-05-07 14:52
ComboFix2.txt 2010-05-06 15:10
Vor Suchlauf: 9 Verzeichnis(se), 18.118.512.640 Bytes frei
Nach Suchlauf: 10 Verzeichnis(se), 18.076.876.800 Bytes frei
Current=3 Default=3 Failed=2 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 7E91B8E83B5AB9F952A7649D71A9E5CF
==================================================
HijackThis Log:
========================Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:00:14, on 07.05.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\Alwil Software\Avast4\aswUpdSv.exe
C:\Programme\Alwil Software\Avast4\ashServ.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Programme\Atomic Alarm Clock\AtomicAlarmClock.exe
C:\Programme\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\Alwil Software\Avast4\setup\avast.setup
C:\Programme\Spyware Doctor\BDT\BDTUpdateService.exe
C:\Programme\Java\jre6\bin\jqs.exe
C:\Programme\Roxio\Digital Home 9\RoxioUpnpService9.exe
C:\Programme\Gemeinsame Dateien\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programme\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
https://facebook.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programme\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Programme\Internet Download Manager\IDMIECC.dll
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Programme\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Programme\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Programme\Spyware Doctor\BDT\PCTBrowserDefender.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Programme\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programme\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Programme\TechSmith\SnagIt 8\SnagItIEAddin.dll
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Programme\Spyware Doctor\BDT\PCTBrowserDefender.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [SkinClock] C:\Programme\Atomic Alarm Clock\AtomicAlarmClock.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Mozilla.lnk = C:\Programme\Mozilla Firefox\firefox.exe
O8 - Extra context menu item: Download all links with IDM - C:\Programme\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Programme\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Programme\Internet Download Manager\IEExt.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
http://download.mcafee.com/molbin/iss-loc/mcfscan/3,0,0,5964/mcfscan.cabO18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programme\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programme\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programme\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programme\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Browser Defender Update Service - Threat Expert Ltd. - C:\Programme\Spyware Doctor\BDT\BDTUpdateService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programme\Java\jre6\bin\jqs.exe
O23 - Service: MBAMService - Unknown owner - C:\MalwarebytesPortable\App\Malwarebytes\mbamservice.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Programme\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Programme\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Programme\Gemeinsame Dateien\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Programme\Gemeinsame Dateien\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Programme\Gemeinsame Dateien\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Programme\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Programme\Spyware Doctor\pctsSvc.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Programme\Yahoo!\SoftwareUpdate\YahooAUService.exe
--
End of file - 7332 bytes
============================ hmmm...
best regards...