Code:
Alles auswählen Aufklappen ATTFilter
ComboFix 12-11-03.02 - Pc 03.11.2012 19:58:47.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.49.1031.18.2815.1768 [GMT 1:00]
ausgeführt von:: c:\users\Pc\Desktop\ComboFix.exe
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Install.exe
c:\program files\BrowserCompanion
c:\program files\BrowserCompanion\blabbers-ch.crx
c:\program files\BrowserCompanion\blabbers-ff-full.xpi
c:\program files\BrowserCompanion\logo.ico
c:\program files\BrowserCompanion\tdataprotocol.dll
c:\program files\BrowserCompanion\terms.lnk.url
c:\program files\BrowserCompanion\toolbar.dll
c:\program files\BrowserCompanion\uninstall.exe
c:\program files\BrowserCompanion\updatebhoWin32.dll
c:\program files\BrowserCompanion\updater.ini
c:\program files\BrowserCompanion\widgetserv.exe
c:\program files\Web Assistant\ExTEnsion32.dll
c:\users\Pc\Music\Neuer Ordner (2)\desktop_1.ini
c:\users\Pc\Music\Neuer Ordner (2)\desktop_2.ini
c:\users\Pc\uninstall.exe
c:\windows\system32\roboot.exe
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\regtlib.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2012-10-03 bis 2012-11-03 ))))))))))))))))))))))))))))))
.
.
2012-11-03 19:11 . 2012-11-03 19:11 -------- d-----w- c:\users\Pc\AppData\Local\temp
2012-11-03 19:11 . 2012-11-03 19:11 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-11-03 18:17 . 2012-10-30 22:51 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-11-03 18:17 . 2012-10-30 22:51 361032 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-11-03 18:17 . 2012-11-03 18:17 -------- d-----w- c:\windows\LastGood
2012-11-03 18:17 . 2012-10-30 22:51 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-11-03 18:17 . 2012-10-30 22:51 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-11-03 18:17 . 2012-10-30 22:51 738504 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-11-03 18:17 . 2012-10-30 22:51 58680 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-11-03 18:16 . 2012-10-30 22:51 41224 ----a-w- c:\windows\avastSS.scr
2012-11-03 18:16 . 2012-10-30 22:50 227648 ----a-w- c:\windows\system32\aswBoot.exe
2012-11-03 18:15 . 2012-11-03 18:15 42760 ----a-w- c:\windows\system32\certsentry.dll
2012-11-03 18:15 . 2012-11-03 18:15 -------- d-----w- c:\programdata\AVAST Software
2012-11-03 18:15 . 2012-11-03 18:15 -------- d-----w- c:\program files\AVAST Software
2012-11-03 18:13 . 2012-11-03 18:13 -------- d-----w- c:\programdata\Comodo
2012-11-03 18:12 . 2012-11-03 18:12 -------- d-----w- c:\users\Pc\AppData\Local\Comodo
2012-11-03 18:12 . 2012-11-03 18:13 -------- d-----w- c:\program files\Comodo
2012-11-03 17:38 . 2012-11-03 17:38 -------- d-----w- c:\programdata\CheckPoint
2012-11-02 14:09 . 2012-10-17 00:32 6918632 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{818B4FD5-C9DF-44D7-9788-4007A5E2528D}\mpengine.dll
2012-10-27 12:21 . 2012-10-27 12:21 -------- d-----w- c:\program files\CPUID
2012-10-26 09:37 . 2012-10-26 09:40 -------- d-----w- c:\users\Gast
2012-10-22 19:53 . 2012-11-03 15:57 -------- d-----w- c:\users\Pc\.rainlendar2
2012-10-22 19:52 . 2012-10-22 19:52 -------- d-----w- c:\program files\Rainlendar2
2012-10-05 00:32 . 2012-10-05 00:32 82952 ----a-w- c:\windows\system32\drivers\inspect.sys
2012-10-05 00:32 . 2012-10-05 00:32 42776 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2012-10-05 00:32 . 2012-10-05 00:32 494416 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
2012-10-05 00:32 . 2012-10-05 00:32 19632 ----a-w- c:\windows\system32\drivers\cmderd.sys
2012-10-05 00:32 . 2012-10-05 00:32 34024 ----a-w- c:\windows\system32\cmdcsr.dll
2012-10-05 00:32 . 2012-10-05 00:32 301264 ----a-w- c:\windows\system32\guard32.dll
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-29 17:54 . 2012-01-03 21:26 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-10-27 20:23 . 2012-10-27 20:23 261600 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 22:50 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Rainlendar2"="c:\program files\Rainlendar2\Rainlendar2.exe" [2012-07-02 2498048]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2006-11-09 3784704]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-07-11 90112]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-08-10 348664]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-04-04 446392]
"AdobeCS6ServiceManager"="c:\program files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-03-09 1073312]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-04-18 421888]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 2178832]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984]
"COMODO"="c:\program files\COMODO\COMODO GeekBuddy\CLPSLA.exe" [2011-11-23 208184]
"CPA"="c:\program files\COMODO\COMODO GeekBuddy\VALA.exe" [2011-11-23 182584]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2012-10-05 6756048]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
.
c:\users\Pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
tbhcn.lnk - c:\users\Pc\AppData\Roaming\BrowserCompanion\tbhcn.exe [2012-7-2 695448]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\guard32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - 13129354
*NewlyCreated* - ASWFSBLK
*NewlyCreated* - ASWMBR
*NewlyCreated* - ASWMONFLT
*NewlyCreated* - ASWRDR
*NewlyCreated* - ASWSNX
*NewlyCreated* - ASWSP
*NewlyCreated* - ASWTDI
*NewlyCreated* - COMHOST
*NewlyCreated* - INSPECT
*Deregistered* - 13129354
*Deregistered* - aswMBR
.
Inhalt des "geplante Tasks" Ordners
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.searchplusnetwork.com/?sp=vit4
IE: {{7644E42D-B096-457F-8B5B-901238FC81AE} - c:\program files\ICQ7.6\ICQ.exe
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\Pc\AppData\Roaming\Mozilla\Firefox\Profiles\rcnr80y1.default\
FF - prefs.js: browser.search.selectedEngine - Plus! Network
FF - prefs.js: browser.startup.homepage - google.de
FF - prefs.js: keyword.URL - hxxp://www.searchplusnetwork.com/?sp=vit4&q=
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
FF - user.js: extensions.incredibar_i.newTab - false
FF - user.js: extensions.incredibar_i.tlbrSrchUrl - hxxp://mystart.Incredibar.com/?a=6PQfPJPC0A&loc=IB_TB&i=26&search=
FF - user.js: extensions.incredibar_i.id - bac7fcca000000000000001c4afe466d
FF - user.js: extensions.incredibar_i.instlDay - 15488
FF - user.js: extensions.incredibar_i.vrsn - 1.5.11.14
FF - user.js: extensions.incredibar_i.vrsni - 1.5.11.14
FF - user.js: extensions.incredibar_i.vrsnTs - 1.5.11.1423:08
FF - user.js: extensions.incredibar_i.prtnrId - Incredibar
FF - user.js: extensions.incredibar_i.prdct - incredibar
FF - user.js: extensions.incredibar_i.aflt - orgnl
FF - user.js: extensions.incredibar_i.smplGrp - none
FF - user.js: extensions.incredibar_i.tlbrId - base
FF - user.js: extensions.incredibar_i.instlRef -
FF - user.js: extensions.incredibar_i.dfltLng -
FF - user.js: extensions.incredibar_i.excTlbr - false
FF - user.js: extensions.incredibar_i.ms_url_id -
FF - user.js: extensions.incredibar_i.upn2 - 6PQfPJPC0A
FF - user.js: extensions.incredibar_i.upn2n - 92541888025477972
FF - user.js: extensions.incredibar_i.productid - 26
FF - user.js: extensions.incredibar_i.installerproductid - 26
FF - user.js: extensions.incredibar_i.did - 10643
FF - user.js: extensions.incredibar_i.ppd - 1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
URLSearchHooks-{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - (no file)
URLSearchHooks-{1392b8d2-5c05-419f-a8f6-b9f15a596612} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{D40B90B4-D3B1-4D6B-A5D7-DC041C1B76C0} - (no file)
HKLM-Run-Freecorder FLV Service - c:\program files\Freecorder\FLVSrvc.exe
AddRemove-BrowserCompanion - c:\program files\BrowserCompanion\uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2012-11-03 20:11
Windows 6.0.6000 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-446868349-3723851372-2455889026-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*Lß]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-446868349-3723851372-2455889026-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*Lß\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
Zeit der Fertigstellung: 2012-11-03 20:15:09
ComboFix-quarantined-files.txt 2012-11-03 19:15
.
Vor Suchlauf: 9 Verzeichnis(se), 365.204.070.400 Bytes frei
Nach Suchlauf: 11 Verzeichnis(se), 365.277.982.720 Bytes frei
.
- - End Of File - - D425770B3089603F2D345C06DDBE24F4