Below is the result.
I also got a warning from windows:
PEV.cfxxe the file c:\Dokume~1\ulrike~1\lokale~1\Temp\JETC563.tmp is demaged. Please run CHKDSK
What should I do with this message?
—————————————————-
ComboFix 10-05-12.01 - Ulrike Klöppel 12.05.2010 21:38:43.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.49.1031.18.1014.599 [GMT 1:00]
ausgeführt von:: c:\dokumente und einstellungen\Ulrike Klöppel\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
Infizierte Kopie von c:\windows\system32\drivers\shpf.sys wurde gefunden und desinfiziert
Kopie von - Kitty had a snack

wurde wiederhergestellt
.
((((((((((((((((((((((( Dateien erstellt von 2010-04-12 bis 2010-05-12 ))))))))))))))))))))))))))))))
.
2010-05-12 20:44 . 2010-05-12 20:44 ——– d—–w- c:\windows\LastGood
2010-05-11 07:27 . 2010-05-11 07:27 ——– d—–w- c:\programme\RegistryRestore_ERUNT
2010-05-11 02:23 . 2010-05-11 02:23 ——– d-s—w- c:\dokumente und einstellungen\NetworkService\UserData
2010-05-10 15:56 . 2010-04-29 14:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-10 15:56 . 2010-05-10 15:56 ——– d—–w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\Malwarebytes
2010-05-10 15:56 . 2010-04-29 14:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-05-10 15:56 . 2010-05-10 15:56 ——– d—–w- c:\programme\Malwarebytes' Anti-Malware
2010-05-10 14:40 . 2010-05-10 14:40 ——– d—–w- c:\programme\Trend Micro
2010-05-10 14:18 . 2010-05-10 12:25 15880 —-a-w- c:\windows\system32\lsdelete.exe
2010-05-10 12:25 . 2010-02-04 15:53 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys
2010-05-10 12:25 . 2010-05-10 12:25 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-05-10 12:22 . 2010-05-10 12:22 ——– dc-h–w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-05-10 12:22 . 2010-02-04 15:53 2954656 -c–a-w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}\Ad-AwareInstaller.exe
2010-05-10 12:21 . 2010-05-10 12:25 ——– d—–w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\Lavasoft
2010-05-10 12:21 . 2010-05-10 12:22 ——– d—–w- c:\programme\Lavasoft
2010-05-09 19:32 . 2010-05-09 19:32 ——– d—–w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\TEMP
2010-05-09 19:32 . 2010-05-09 19:34 ——– d—–w- c:\programme\SpywareBlaster
2010-04-30 23:48 . 2010-04-30 23:48 ——– d—–w- c:\programme\iPod
2010-04-30 23:48 . 2010-04-30 23:49 ——– d—–w- c:\programme\iTunes
2010-04-30 23:48 . 2010-04-30 23:49 ——– d—–w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-04-30 23:42 . 2010-04-30 23:43 ——– d—–w- c:\programme\QuickTime
2010-04-30 23:38 . 2010-04-30 23:38 ——– d—–w- c:\programme\Bonjour
2010-04-30 23:34 . 2010-04-30 23:34 73000 —-a-w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-12 20:22 . 2008-04-08 06:05 ——– d—–w- c:\programme\Mozilla Thunderbird
2010-05-11 08:15 . 2009-08-02 16:02 ——– d—–w- c:\programme\Windows Desktop Search
2010-05-10 23:09 . 2006-03-31 01:36 85594 —-a-w- c:\windows\system32\perfc007.dat
2010-05-10 23:09 . 2006-03-31 01:36 460908 —-a-w- c:\windows\system32\perfh007.dat
2010-05-07 13:10 . 2008-07-24 08:23 ——– d—–w- c:\programme\SyncBack
2010-04-30 23:48 . 2009-12-26 07:50 ——– d—–w- c:\programme\Gemeinsame Dateien\Apple
2010-04-22 18:02 . 2009-11-23 11:15 ——– d—–w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\FreePDF
2010-04-10 21:37 . 2006-03-31 11:52 ——– d—–w- c:\programme\Gemeinsame Dateien\Java
2010-04-10 21:33 . 2006-03-31 11:53 ——– d—–w- c:\programme\Java
2010-04-09 01:03 . 2010-04-09 01:03 ——– d—–w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\Langenscheidt
2010-04-09 01:02 . 2010-04-09 01:01 ——– d—–w- c:\programme\Vokabeltrainer 4-Demo
2010-04-08 20:59 . 2010-04-08 20:59 38844 —ha-w- c:\windows\system32\mlfcache.dat
2010-04-08 12:20 . 2010-04-08 12:20 91424 —-a-w- c:\windows\system32\dnssd.dll
2010-04-08 12:20 . 2010-04-08 12:20 107808 —-a-w- c:\windows\system32\dns-sd.exe
2010-04-01 12:57 . 2010-04-01 12:57 ——– d—–w- c:\programme\Gemeinsame Dateien\Skype
2010-03-14 18:19 . 2008-12-16 21:14 ——– d—–w- c:\programme\ElsterFormular
2010-03-14 18:19 . 2006-03-31 10:32 ——– d–h–w- c:\programme\InstallShield Installation Information
2010-03-09 11:09 . 2006-03-31 01:36 430080 —-a-w- c:\windows\system32\vbscript.dll
2010-03-09 03:28 . 2008-12-12 07:41 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-03-01 08:05 . 2009-03-20 22:07 124784 —-a-w- c:\windows\system32\drivers\avipbb.sys
2010-02-26 05:41 . 2006-03-31 01:36 672768 —-a-w- c:\windows\system32\wininet.dll
2010-02-26 05:41 . 2006-03-31 01:35 81920 —-a-w- c:\windows\system32\ieencode.dll
2010-02-24 13:11 . 2006-03-31 01:35 455680 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-21 10:31 . 2010-02-21 10:31 724992 —-a-w- c:\windows\iun6002.exe
2010-02-16 19:04 . 2006-03-31 01:35 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 19:04 . 2004-08-04 00:50 2027008 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-16 12:24 . 2009-03-20 22:07 60936 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2010-02-12 10:03 . 2010-03-10 20:51 293376 ——w- c:\windows\system32\browserchoice.exe
2010-02-12 04:33 . 2006-03-31 01:35 100864 —-a-w- c:\windows\system32\6to4svc.dll
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SsAAD.exe"="c:\progra~1\Sony\SONICS~1\SsAAD.exe" [2006-05-08 81920]
"SpybotSD TeaTimer"="c:\programme\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Skype"="c:\programme\Skype\Phone\Skype.exe" [2010-03-09 26100520]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\programme\Apoint\Apoint.exe" [2004-11-17 118784]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-17 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-17 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-17 118784]
"Mouse Suite 98 Daemon"="ICO.EXE" [2007-01-26 49152]
"EOUApp"="c:\programme\Intel\Wireless\Bin\EOUWiz.exe" [2006-02-28 569413]
"SonyPowerCfg"="c:\programme\Sony\VAIO Power Management\SPMgr.exe" [2006-01-26 212992]
"ISBMgr.exe"="c:\programme\Sony\ISB Utility\ISBMgr.exe" [2004-02-20 32768]
"zBrowser Launcher"="c:\programme\Logitech\iTouch\iTouch.exe" [2003-12-01 892928]
"Logitech Utility"="Logi_MwX.Exe" [2003-11-07 19968]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-06-20 7561216]
"IntelZeroConfig"="c:\programme\Intel\Wireless\bin\ZCfgSvc.exe" [2006-07-03 802816]
"IntelWireless"="c:\programme\Intel\Wireless\Bin\ifrmewrk.exe" [2006-07-02 700416]
"avgnt"="c:\programme\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]
"UsbBoost"="c:\programme\UsbBoost\TurboHddUsb.exe" [2009-08-11 3788800]
"FreePDF Assistant"="c:\programme\FreePDF_XP\fpassist.exe" [2009-09-05 385024]
"CanonMyPrinter"="c:\programme\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 1603152]
"SSBkgdUpdate"="c:\programme\Gemeinsame Dateien\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="c:\programme\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"WrtMon.exe"="c:\windows\system32\spool\drivers\w32x86\3\WrtMon.exe" [2006-09-20 20480]
"QuickTime Task"="c:\programme\QuickTime\QTTask.exe" [2010-03-17 421888]
"iTunesHelper"="c:\programme\iTunes\iTunesHelper.exe" [2010-04-28 142120]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\dokumente und einstellungen\All Users\Startmen\Programme\Autostart\
Acrobat Assistant.lnk - c:\programme\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-5-15 217193]
Microsoft Office.lnk - c:\programme\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2005-05-20 15:42 73728 —-a-w- c:\windows\system32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0lsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"updateMgr"="c:\programme\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Microsoft Works Portfolio"=c:\programme\Microsoft Works\WksSb.exe /AllUsers
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programme\\Sony\\VAIO Media 5.0\\Vc.exe"=
"c:\\Programme\\FileMaker\\FileMaker Pro 8.5\\FileMaker Pro.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programme\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Programme\\Bonjour\\mDNSResponder.exe"=
"c:\\Programme\\iTunes\\iTunes.exe"=
"c:\\Programme\\Skype\\Phone\\Skype.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [10.05.2010 13:25 64288]
R0 shpf;Sony HDD Protection Filter Driver;c:\windows\system32\drivers\shpf.sys [31.03.2006 02:36 9216]
R1 FNETURPX;FNETURPX;c:\windows\system32\drivers\FNETURPX.SYS [11.08.2009 20:39 7936]
R2 AntiVirSchedulerService;Avira AntiVir Planer;c:\programme\Avira\AntiVir Desktop\sched.exe [20.03.2009 23:07 135336]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\programme\Lavasoft\Ad-Aware\AAWService.exe [04.02.2010 16:52 1285864]
R3 SPI;Sony Programmable I/O Control Device;c:\windows\system32\drivers\SonyPI.sys [31.03.2006 02:36 71961]
R3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\drivers\tap0801.sys [01.10.2006 13:37 26624]
R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [31.03.2006 02:36 226304]
S0 IFP300;iRiver Internet Audio Player IFP-300;c:\windows\system32\DRIVERS\ifp300.sys –> c:\windows\system32\DRIVERS\ifp300.sys [?]
S3 FNETTBOH;FNETTBOH;c:\windows\system32\drivers\FNETTBOH.SYS [11.08.2009 20:39 23680]
S3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\system32\drivers\SonyImgF.sys [31.03.2006 02:36 29184]
.
Inhalt des "geplante Tasks" Ordners
2010-05-10 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\programme\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 12:25]
2010-05-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programme\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
.
——- Zusätzlicher Suchlauf ——-
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = hxxp://www.club-vaio.com/de/
uInternet Settings,ProxyOverride =
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
IE: Übertragen mit Image Converter 2 Plus - c:\programme\Sony\Image Converter 2\menu.htm
Trusted Zone: microsoft.com\windowsupdate
Trusted Zone: microsoft.com\www.update
Trusted Zone: whatthetech.com\forums
FF - ProfilePath - c:\dokumente und einstellungen\Ulrike Klöppel\Anwendungsdaten\Mozilla\Firefox\Profiles\w8osac6o.default\
FF - component: c:\programme\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
FF - plugin: c:\programme\Picasa2\npPicasa2.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX Richtlinien —-
c:\programme\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\programme\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\programme\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\programme\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\programme\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\programme\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\programme\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\programme\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\programme\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\programme\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
MSConfigStartUp-DriverCure - c:\programme\ParetoLogic\DriverCure\DriverCure.exe
MSConfigStartUp-VAIO Update 3 - c:\programme\Sony\VAIO Update 3\VAIOUpdt.exe
AddRemove-AFPL Ghostscript 8.54 - c:\programme\Ghostscript\uninstgs.exe
AddRemove-AFPL Ghostscript Fonts - c:\programme\Ghostscript\uninstgs.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-05-12 21:50
Windows 5.1.2600 Service Pack 3 NTFS
Scanne versteckte Prozesse…
Scanne versteckte Autostarteinträge…
Scanne versteckte Dateien…
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
**************************************************************************
.
——————— Durch laufende Prozesse gestartete DLLs ———————
- - - - - - - > 'winlogon.exe'(980)
c:\windows\system32\VESWinlogon.dll
.
Zeit der Fertigstellung: 2010-05-12 21:54:57
ComboFix-quarantined-files.txt 2010-05-12 20:54
Vor Suchlauf: 9.859.026.944 Bytes frei
Nach Suchlauf: 9.926.950.912 Bytes frei
WindowsXP-KB310994-SP2-Home-BootDisk-DEU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
- - End Of File - - 710DAF4CF52C2CB2D6A59F1F2A27BDD7