AW: Andauernde Störungen
Super!!!
Das Rootkit scheint gelöscht zu sein. Und ich bin seit 5 Minuten im Internet ohne Absturz.
Leider musste ich feststellen das die Störungen wieder da sind. Auch mit normalen CPU Takt.
Und hier ist der Bericht:
SDFix: Version 1.240
Run by Chaos on 09.12.2009 at 17:40
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
Service asc3550p - Deleted after Reboot
Checking Files :
Trojan Files Found:
C:\Dokumente und Einstellungen\Chaos\Lokale Einstellungen\Temp\NEW5A.tmp.exe - Deleted
C:\WINDOWS\system32\drivers\asc3550p.sys - Deleted
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-09 17:47:13
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:0000014a
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\\Programme\\Mozilla Firefox\\firefox.exe"="C:\\Programme\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"
"C:\\Programme\\VideoLAN\\VLC\\vlc.exe"="C:\\Programme\\VideoLAN\\VLC\\vlc.exe:*:Enabled:VLC media player"
"C:\\Programme\\Bonjour\\mDNSResponder.exe"="C:\\Programme\\Bonjour\\mDNSResponder.exe:*:Enabled
onjour"
"C:\\Programme\\Electronic Arts\\EADM\\Core.exe"="C:\\Programme\\Electronic Arts\\EADM\\Core.exe:*:Enabled:EA Download Manager"
"C:\\Programme\\iTunes\\iTunes.exe"="C:\\Programme\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Programme\\Rockstar Games\\Grand Theft Auto IV\\LaunchGTAIV.exe"="C:\\Programme\\Rockstar Games\\Grand Theft Auto IV\\LaunchGTAIV.exe:*:Enabled:Grand Theft Auto IV"
"C:\\Programme\\Rockstar Games\\Grand Theft Auto IV\\GTAIV.exe"="C:\\Programme\\Rockstar Games\\Grand Theft Auto IV\\GTAIV.exe:*:Enabled:Grand Theft Auto IV"
"C:\\Programme\\Activision\\Wolfenstein\\MP\\Wolf2MP.exe"="C:\\Programme\\Activision\\Wolfenstein\\MP\\Wolf2MP.exe:*:Enabled:Wolfenstein(TM)"
"C:\\Programme\\Activision\\Wolfenstein\\MP\\Wolf2MPLite.exe"="C:\\Programme\\Activision\\Wolfenstein\\MP\\Wolf2MPLite.exe:*:Enabled:Wolfenstein(TM)"
"C:\\Programme\\AVG\\AVG9\\avgemc.exe"="C:\\Programme\\AVG\\AVG9\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\Programme\\AVG\\AVG9\\avgupd.exe"="C:\\Programme\\AVG\\AVG9\\avgupd.exe:*:Enabled:avgupd.exe"
"C:\\Programme\\AVG\\AVG9\\avgnsx.exe"="C:\\Programme\\AVG\\AVG9\\avgnsx.exe:*:Enabled:avgnsx.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
Remaining Files :
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes :
Tue 9 Sep 2008 16,823,592 A..H. --- "C:\DwgDocumentMgrNET.dll"
Sat 7 Feb 2009 0 A.SH. --- "C:\Dokumente und Einstellungen\All Users\DRM\Cache\Indiv01.tmp"
Sat 5 Dec 2009 8,121 ...HR --- "C:\Dokumente und Einstellungen\Chaos\Anwendungsdaten\SecuROM\UserData\securom_v7_01.bak"
Fri 6 Mar 2009 96,072 ...H. --- "C:\Programme\Gemeinsame Dateien\aol\TopSpeed\3.0\WBUnins.exe"
Finished!