![]() |
|
Plagegeister aller Art und deren Bekämpfung: Backdoorporgramm Problem!Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #12 |
| ![]() Backdoorporgramm Problem! sooo hoffe das ich alles richtig gemacht habe ![]() Combofix Logfile: Code:
ATTFilter ComboFix 10-09-17.04 - Alex und Corinna 19.09.2010 13:56:14.1.4 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.3327.2220 [GMT 2:00] ausgeführt von:: c:\users\Alex und Corinna\Desktop\cofi.exe SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . C:\fukkuukkkk.exe c:\fukkuukkkk.exe\config.bin c:\users\Alex und Corinna\AppData\Roaming\Microsoft\Windows\Recent\patch.log c:\users\Alex und Corinna\AppData\Roaming\windows c:\users\Alex und Corinna\AppData\Roaming\windows\logs.dat c:\users\Alex und Corinna\SETUP1.EXE c:\windows\system32\404Fix.exe c:\windows\system32\Agent.OMZ.Fix.exe c:\windows\system32\dumphive.exe c:\windows\system32\IEDFix.C.exe c:\windows\system32\IEDFix.exe c:\windows\system32\o4Patch.exe c:\windows\system32\SrchSTS.exe c:\windows\system32\test c:\windows\system32\tmp.reg c:\windows\system32\ui c:\windows\system32\ui\BANNER\LOADINGEVENT2.SOR c:\windows\system32\ui\BANNER\LOADINGIMGOPT.SOR c:\windows\system32\ui\BANNER\NOTICE_BANNER2.SOR c:\windows\system32\ui\BANNER\NOTICE_BANNER3.SOR c:\windows\system32\ui\BANNER\NOTICE_BANNER4.SOR c:\windows\system32\VACFix.exe c:\windows\system32\VCCLSID.exe c:\windows\system32\WS2Fix.exe c:\windows\system32\kernel32.dll . . . ist infiziert!! . ((((((((((((((((((((((( Dateien erstellt von 2010-08-19 bis 2010-09-19 )))))))))))))))))))))))))))))) . 2010-09-19 12:06 . 2010-09-19 12:06 -------- d-----w- c:\users\Default\AppData\Local\temp 2010-09-18 18:57 . 2010-09-19 12:06 0 ----a-w- c:\windows\system32\Access.dat 2010-09-18 18:55 . 2010-09-18 19:24 -------- d-----w- c:\users\Alex und Corinna\AppData\Roaming\Tunngle 2010-09-18 18:55 . 2010-09-18 18:55 -------- d-----w- c:\programdata\Tunngle 2010-09-18 18:55 . 2009-09-16 06:02 27136 ----a-w- c:\windows\system32\drivers\tap0901t.sys 2010-09-18 18:55 . 2010-09-18 19:23 -------- d-----w- c:\program files\Tunngle 2010-09-17 19:53 . 2010-09-17 19:53 -------- d-----w- c:\users\Alex und Corinna\AppData\Roaming\Lionhead Studios 2010-09-17 19:52 . 2010-09-17 19:52 -------- d-sh--w- c:\windows\ftpcache 2010-09-17 19:47 . 2010-09-17 19:47 -------- d-----w- c:\programdata\Lionhead Studios 2010-09-17 14:33 . 2010-09-17 14:33 -------- d-----w- c:\program files\Governor of Poker 2010-09-17 14:33 . 2010-09-17 14:33 -------- d-----w- c:\windows\Governor of Poker 2010-09-16 14:04 . 2010-09-16 14:18 -------- d-----w- c:\users\Alex und Corinna\AppData\Local\OpenCandy 2010-09-16 14:04 . 2010-09-16 14:04 331304 ----a-w- c:\users\Alex und Corinna\AppData\Roaming\OpenCandy\OpenCandy_F2C2083185B544869FA22ED95984C682\DLMgr_3_1.6.44.exe 2010-09-16 14:04 . 2010-09-16 14:04 -------- d-----w- c:\users\Alex und Corinna\AppData\Roaming\OpenCandy 2010-09-16 13:14 . 2010-09-16 13:14 -------- d-----w- C:\_OTL 2010-09-15 16:49 . 2010-09-15 16:49 -------- d-----w- c:\users\Alex und Corinna\AppData\Roaming\ProgSense 2010-09-15 16:48 . 2010-09-16 14:19 -------- d-----w- C:\downloads 2010-09-15 16:48 . 2010-09-15 16:48 -------- d-----w- c:\users\Alex und Corinna\AppData\Roaming\GrabPro 2010-09-15 16:48 . 2010-09-17 13:59 -------- d-----w- c:\users\Alex und Corinna\AppData\Roaming\Orbit 2010-09-15 15:21 . 2010-09-15 16:59 -------- d-----w- c:\program files\Common Files\Real 2010-09-15 14:14 . 2010-04-05 17:02 317952 ----a-w- c:\windows\system32\MP4SDECD.DLL 2010-09-15 14:14 . 2010-04-16 16:46 502272 ----a-w- c:\windows\system32\usp10.dll 2010-09-15 14:14 . 2010-08-17 14:11 128000 ----a-w- c:\windows\system32\spoolsv.exe 2010-09-15 14:13 . 2010-05-27 20:08 739328 ----a-w- c:\windows\system32\inetcomm.dll 2010-09-14 16:31 . 2010-09-14 16:31 973496 ----a-w- c:\programdata\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav11\11.0.0.232\updater.dll 2010-09-14 16:31 . 2010-09-14 16:31 88760 ----a-w- c:\programdata\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav11\11.0.0.232\libola.dll 2010-09-14 16:30 . 2010-09-14 16:31 973496 ----a-w- c:\programdata\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav11\11.0.0.232\updater.dll 2010-09-13 14:36 . 2010-09-13 14:36 57344 ----a-w- c:\programdata\DivX\RunAsUser\RUNASUSERPROCESS.dll 2010-09-13 14:35 . 2010-09-13 14:18 185640 ----a-w- c:\programdata\DivX\Setup\finishPlugin.dll 2010-09-13 14:35 . 2010-09-13 14:17 1062184 ----a-w- c:\programdata\DivX\Setup\Resource.dll 2010-09-13 14:35 . 2010-09-13 14:17 850200 ----a-w- c:\programdata\DivX\Setup\DivXSetup.exe 2010-09-13 14:35 . 2010-09-13 14:35 56765 ----a-w- c:\programdata\DivX\DivXPlusShortcuts\Uninstaller.exe 2010-09-13 14:35 . 2010-09-13 14:35 56997 ----a-w- c:\programdata\DivX\WebPlayer\Uninstaller.exe 2010-09-13 14:35 . 2010-09-13 14:35 57691 ----a-w- c:\programdata\DivX\Player\Uninstaller.exe 2010-09-13 14:35 . 2010-09-13 14:35 53600 ----a-w- c:\programdata\DivX\Update\Uninstaller.exe 2010-09-13 14:34 . 2010-09-13 14:34 84063 ----a-w- c:\programdata\DivX\TransferWizard\Uninstaller.exe 2010-09-13 14:34 . 2010-09-13 14:34 57054 ----a-w- c:\programdata\DivX\DSDesktopComponents\Uninstaller.exe 2010-09-13 14:34 . 2010-09-13 14:34 57532 ----a-w- c:\programdata\DivX\DSASPDecoder\Uninstaller.exe 2010-09-13 14:34 . 2010-09-13 14:34 54166 ----a-w- c:\programdata\DivX\DSAVCDecoder\Uninstaller.exe 2010-09-13 14:34 . 2010-09-13 14:34 56458 ----a-w- c:\programdata\DivX\DivXDecoderShortcut\Uninstaller.exe 2010-09-13 14:34 . 2010-09-13 14:34 54174 ----a-w- c:\programdata\DivX\DSAACDecoder\Uninstaller.exe 2010-09-13 14:34 . 2010-09-13 14:34 54153 ----a-w- c:\programdata\DivX\DFXPlugin\Uninstaller.exe 2010-09-13 14:34 . 2010-09-13 14:34 54128 ----a-w- c:\programdata\DivX\Converter\Uninstaller.exe 2010-09-13 14:34 . 2010-09-13 14:34 54644 ----a-w- c:\programdata\DivX\TranscodeEngine\Uninstaller.exe 2010-09-13 14:34 . 2010-09-13 14:34 57409 ----a-w- c:\programdata\DivX\ControlPanel\Uninstaller.exe 2010-09-13 14:34 . 2010-09-13 14:34 54101 ----a-w- c:\programdata\DivX\MPEG2Plugin\Uninstaller.exe 2010-09-13 14:33 . 2010-09-13 14:33 52963 ----a-w- c:\programdata\DivX\MSVC80CRTRedist\Uninstaller.exe 2010-09-13 14:33 . 2010-09-13 14:33 54073 ----a-w- c:\programdata\DivX\Qt4.5\Uninstaller.exe 2010-09-13 14:33 . 2010-09-13 14:33 -------- d-----w- c:\program files\Common Files\DivX Shared 2010-09-13 14:33 . 2010-09-13 14:33 56969 ----a-w- c:\programdata\DivX\ASPEncoder\Uninstaller.exe 2010-09-13 14:17 . 2010-09-13 14:17 144696 ----a-w- c:\programdata\DivX\RunAsUser\RUNASUSERPROCESS.exe 2010-09-13 14:17 . 2010-09-13 14:35 -------- d-----w- c:\programdata\DivX 2010-09-12 09:26 . 2010-09-12 09:26 -------- d-----w- c:\users\Alex und Corinna\AppData\Roaming\Stardock 2010-09-12 09:26 . 2010-09-12 09:26 -------- dc-h--w- c:\programdata\{A3A26C56-02C3-4F76-A033-12EE2FB52AE6} 2010-09-12 09:26 . 2010-06-22 19:49 3349784 -c--a-w- c:\programdata\{A3A26C56-02C3-4F76-A033-12EE2FB52AE6}\Fences.exe 2010-09-12 09:26 . 2010-09-12 09:26 -------- d-----w- c:\program files\Stardock 2010-09-12 09:25 . 2010-09-12 09:25 -------- d-----w- c:\users\Alex und Corinna\AppData\Local\PackageAware 2010-09-11 16:32 . 2010-09-11 16:32 -------- d-----w- c:\users\Alex und Corinna\AppData\Roaming\Malwarebytes 2010-09-11 16:32 . 2010-04-29 10:19 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-09-11 16:32 . 2010-09-11 16:32 -------- d-----w- c:\programdata\Malwarebytes 2010-09-11 16:32 . 2010-09-11 18:47 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2010-09-11 16:32 . 2010-04-29 10:19 20952 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-09-10 15:01 . 2010-09-10 15:03 -------- d-----w- c:\users\Alex und Corinna\AppData\Roaming\vlc 2010-09-10 15:01 . 2010-09-10 15:01 -------- d-----w- c:\program files\VideoLAN 2010-09-06 14:57 . 2010-09-06 14:57 -------- d-----w- c:\program files\PESEdit 2010-09-03 16:45 . 2010-09-03 16:45 -------- d-----w- c:\program files\Common Files\Java 2010-09-03 14:05 . 2010-09-03 14:05 -------- d-----w- c:\program files\DIFX 2010-09-03 14:04 . 2010-09-03 14:05 -------- d-----w- c:\program files\T4E Player 2010-09-01 11:29 . 2010-09-01 11:29 129720 ----a-w- c:\programdata\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav11\11.0.0.232\shellex.dll 2010-09-01 11:29 . 2010-09-01 11:29 113336 ----a-w- c:\programdata\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav11\11.0.0.232\sbstart.exe 2010-09-01 11:29 . 2010-09-01 11:29 170680 ----a-w- c:\programdata\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav11\11.0.0.232\klwtblc.dll 2010-09-01 11:26 . 2010-09-14 16:30 88760 ----a-w- c:\programdata\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav11\11.0.0.232\libola.dll 2010-09-01 11:26 . 2010-09-01 11:26 387768 ----a-w- c:\programdata\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav11\11.0.0.232\ksn_client.dll 2010-09-01 11:26 . 2010-09-01 11:26 191160 ----a-w- c:\programdata\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav11\11.0.0.232\klwtbbho.dll 2010-09-01 11:26 . 2010-09-01 11:26 264888 ----a-w- c:\programdata\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav11\11.0.0.232\esmgr.dll 2010-09-01 11:25 . 2010-09-01 11:25 1037648 ----a-w- c:\programdata\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\temporaryFolder\bases\sw2\klavasyswatch.dll 2010-09-01 11:24 . 2010-09-01 11:25 271696 ----a-w- c:\programdata\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\temporaryFolder\bases\sco\i386\win\sys_critical_obj.dll 2010-09-01 11:01 . 2010-09-02 17:33 288080 ----a-w- c:\programdata\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\temporaryFolder\bases\av\kdb\i386\win\avengine.dll 2010-09-01 10:49 . 2010-09-01 11:29 113933 ----a-w- c:\windows\system32\drivers\klin.dat 2010-09-01 10:49 . 2010-09-01 11:29 97549 ----a-w- c:\windows\system32\drivers\klick.dat 2010-09-01 10:47 . 2010-09-19 12:10 -------- d-----w- c:\programdata\Kaspersky Lab 2010-09-01 10:47 . 2010-09-01 10:47 -------- d-----w- c:\program files\Kaspersky Lab 2010-09-01 10:34 . 2010-09-01 10:34 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files 2010-08-31 20:08 . 2010-09-01 10:27 -------- d-----w- c:\program files\Emsisoft Anti-Malware 2010-08-30 14:41 . 2010-08-30 14:41 -------- d-----w- c:\program files\Apollox Tools 2010-08-30 13:09 . 2010-08-30 13:09 -------- d-----w- c:\windows\system32\pack 2010-08-30 13:09 . 2010-08-30 13:09 -------- d-----w- c:\windows\system32\icon 2010-08-26 13:06 . 2010-08-26 13:06 -------- d-----w- c:\program files\Fifa Master 2010-08-22 11:58 . 2009-11-03 12:07 679936 ----a-w- c:\windows\system32\D3DX81ab.dll 2010-08-22 11:58 . 2009-11-03 12:07 1970176 ----a-w- c:\windows\system32\d3dx9.dll 2010-08-22 11:58 . 2010-09-18 10:50 -------- d-----w- c:\program files\Cheat Engine . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-09-19 12:08 . 2010-03-31 13:08 -------- d-----w- c:\program files\Common Files\Akamai 2010-09-19 11:53 . 2009-06-03 11:59 -------- d-----w- c:\users\Alex und Corinna\AppData\Roaming\ICQ 2010-09-19 08:24 . 2009-10-29 15:53 -------- d-----w- c:\programdata\Spybot - Search & Destroy 2010-09-18 19:00 . 2009-06-03 10:01 71520 ----a-w- c:\users\Alex und Corinna\AppData\Local\GDIPFONTCACHEV1.DAT 2010-09-17 19:52 . 2009-06-03 12:01 -------- d--h--w- c:\program files\InstallShield Installation Information 2010-09-16 13:15 . 2009-10-29 15:53 -------- d-----w- c:\program files\Spybot - Search & Destroy 2010-09-15 18:00 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail 2010-09-15 16:59 . 2010-05-05 18:27 -------- d-----w- c:\program files\Real 2010-09-13 18:34 . 2009-09-15 17:32 -------- d-----w- c:\programdata\CanonIJPLM 2010-09-13 14:39 . 2009-12-06 17:07 -------- d-----w- c:\users\Alex und Corinna\AppData\Roaming\DivX 2010-09-13 14:39 . 2008-01-21 07:15 668882 ----a-w- c:\windows\system32\perfh007.dat 2010-09-13 14:39 . 2008-01-21 07:15 144952 ----a-w- c:\windows\system32\perfc007.dat 2010-09-13 14:39 . 2010-05-31 14:18 -------- d-----w- c:\users\Alex und Corinna\AppData\Roaming\U3 2010-09-13 14:35 . 2009-12-06 16:54 -------- d-----w- c:\program files\DivX 2010-09-13 14:34 . 2009-12-06 16:54 -------- d-----w- c:\program files\Common Files\PX Storage Engine 2010-09-05 11:41 . 2010-04-24 14:12 -------- d-----w- c:\programdata\KONAMI 2010-09-03 16:44 . 2009-06-20 15:17 -------- d-----w- c:\program files\Java 2010-09-02 17:33 . 2010-05-06 13:00 288080 ----a-w- c:\programdata\Kaspersky Lab\AVP11\Bases\avengine.dll 2010-09-02 07:07 . 2010-02-03 05:53 -------- d-----w- c:\users\Alex und Corinna\AppData\Roaming\Daynyd 2010-09-01 14:02 . 2009-06-05 15:21 -------- d-----w- c:\program files\Metin2_Germany 2010-09-01 12:16 . 2009-10-01 15:59 -------- d-----w- c:\users\Alex und Corinna\AppData\Roaming\McLoad 2010-09-01 11:32 . 2010-05-07 10:34 1037648 ----a-w- c:\programdata\Kaspersky Lab\AVP11\Bases\klavasyswatch.dll 2010-09-01 11:32 . 2010-05-07 16:18 271696 ----a-w- c:\programdata\Kaspersky Lab\AVP11\Bases\sys_critical_obj.dll 2010-09-01 10:32 . 2009-06-03 09:58 -------- d-----w- c:\program files\Norman 2010-09-01 10:04 . 2010-01-11 16:12 -------- d-----w- c:\users\Alex und Corinna\AppData\Roaming\Amow 2010-08-31 14:41 . 2010-08-31 14:41 -------- d-----w- c:\program files\Brief-Druckerei 2010-08-23 14:40 . 2010-06-27 10:05 -------- d-----w- c:\program files\ICQ7.2 2010-08-18 15:11 . 2010-08-20 11:53 52224 ----a-w- c:\users\Alex und Corinna\AppData\Roaming\Mozilla\Firefox\Profiles\mxpup8ml.default\extensions\{ef468e5b-5b30-4136-a833-7f2e3a31afdf}\components\FFExternalAlert.dll 2010-08-18 15:11 . 2010-08-20 11:53 101376 ----a-w- c:\users\Alex und Corinna\AppData\Roaming\Mozilla\Firefox\Profiles\mxpup8ml.default\extensions\{ef468e5b-5b30-4136-a833-7f2e3a31afdf}\components\RadioWMPCore.dll 2010-08-17 20:12 . 2010-08-17 20:12 -------- d-----w- c:\program files\Teachmaster 4.3 2010-08-17 20:05 . 2010-08-17 20:05 -------- d-----w- c:\program files\Belearn 7 2010-08-17 11:47 . 2009-06-03 10:02 -------- d-----w- c:\programdata\HDBR31 2010-08-13 14:02 . 2010-08-13 14:02 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_motmodem_01007.Wdf 2010-08-13 14:01 . 2010-08-13 14:01 -------- d-----w- c:\program files\Motorola 2010-08-13 14:01 . 2010-08-13 14:01 -------- d-----w- c:\program files\Common Files\Motorola Shared 2010-08-03 11:13 . 2009-06-20 12:00 -------- d-----w- c:\program files\Atari 2010-08-02 15:41 . 2010-08-02 15:27 -------- d-----w- c:\users\Alex und Corinna\AppData\Roaming\DAEMON Tools Lite 2010-08-02 15:28 . 2010-08-02 15:28 691696 ----a-w- c:\windows\system32\drivers\sptd.sys 2010-08-02 15:28 . 2010-08-02 15:28 -------- d-----w- c:\program files\DAEMON Tools Lite 2010-08-02 15:28 . 2010-08-02 15:27 -------- d-----w- c:\programdata\DAEMON Tools Lite 2010-08-02 14:30 . 2009-08-17 17:04 -------- d-----w- c:\program files\7-Zip 2010-08-01 15:50 . 2010-08-01 15:49 19553 ----a-w- c:\windows\hpqins13.dat 2010-08-01 15:50 . 2010-08-01 15:49 -------- d-----w- c:\program files\HP 2010-08-01 15:49 . 2010-08-01 15:49 -------- d-----w- c:\program files\Common Files\HP 2010-08-01 15:49 . 2010-08-01 15:49 -------- d-----w- c:\programdata\HP 2010-08-01 15:29 . 2010-08-01 15:29 -------- d-----w- c:\program files\Seagrand 2010-08-01 15:29 . 2009-06-03 13:50 -------- d-----w- c:\program files\Common Files\InstallShield 2010-08-01 15:28 . 2009-06-03 09:56 -------- d-----w- c:\program files\Picasa2 2010-08-01 15:14 . 2010-08-01 15:14 -------- d-----w- c:\program files\Foto-Mosaik-Edda 2010-08-01 13:25 . 2010-02-02 14:04 -------- d-----w- c:\programdata\Skype 2010-08-01 13:24 . 2008-09-30 16:08 -------- d-----w- c:\programdata\Microsoft Help 2010-08-01 13:24 . 2008-09-30 16:09 -------- d-----w- c:\program files\Microsoft Works 2010-08-01 13:19 . 2010-05-05 17:42 -------- d-----w- c:\programdata\Norton 2010-08-01 13:19 . 2010-05-05 17:42 -------- d-----w- c:\programdata\Symantec 2010-08-01 13:12 . 2010-03-29 15:11 -------- d-----w- c:\program files\Teamspeak2_RC2 2010-08-01 13:09 . 2009-07-13 11:38 -------- d-----w- c:\program files\alaplaya 2010-07-17 03:00 . 2010-04-30 20:26 423656 ----a-w- c:\windows\system32\deployJava1.dll 2010-06-26 06:05 . 2010-08-13 11:36 916480 ----a-w- c:\windows\system32\wininet.dll 2010-06-26 06:02 . 2010-08-13 11:36 71680 ----a-w- c:\windows\system32\iesetup.dll 2010-06-26 06:02 . 2010-08-13 11:36 109056 ----a-w- c:\windows\system32\iesysprep.dll 2010-06-26 04:25 . 2010-08-13 11:36 133632 ----a-w- c:\windows\system32\ieUnatt.exe 2010-06-24 18:51 . 2009-10-10 14:45 8854 ----a-r- c:\users\Alex und Corinna\AppData\Roaming\Microsoft\Installer\{BA10AC78-E687-4523-8B93-540428FC256F}\Uninstall_Fahrenheit_8C2B6FBDC8D14FA595F7B3231B7D8CBC.exe 2010-06-24 18:51 . 2009-10-10 14:45 10134 ----a-r- c:\users\Alex und Corinna\AppData\Roaming\Microsoft\Installer\{BA10AC78-E687-4523-8B93-540428FC256F}\ARPPRODUCTICON.exe 2010-06-24 18:51 . 2009-10-10 14:09 4286 ----a-r- c:\users\Alex und Corinna\AppData\Roaming\Microsoft\Installer\{BA10AC78-E687-4523-8B93-540428FC256F}\Fahrenheit.exe_B11493A1D18C4B5FAD8D53D777C9C16A.exe 2010-06-21 13:37 . 2010-08-13 11:36 2037760 ----a-w- c:\windows\system32\win32k.sys 2010-08-01 13:53 . 2009-10-29 15:38 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}] 2009-10-19 15:15 1345336 ----a-w- c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2009-10-19 1345336] [HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}] [HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1] [HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}] [HKEY_CLASSES_ROOT\SWEETIE.IEToolbar] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2009-10-19 1345336] [HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}] [HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1] [HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}] [HKEY_CLASSES_ROOT\SWEETIE.IEToolbar] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "WindowsWelcomeCenter"="oobefldr.dll" [2009-04-11 2153472] "Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2008-02-26 443968] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-07-08 13535776] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-07-08 92704] "RtHDVCpl"="RtHDVCpl.exe" [2008-08-27 6281760] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672] "EnergySettings"="c:\program files\Fujitsu Siemens Computers\Energy Settings\EnergySettings.exe" [2008-09-19 113664] "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-08-01 30192] "FSCRecovery"="c:\program files\Fujitsu Siemens Computers\Fujitsu Siemens Computers Recovery\FSCRecoveryReminder.exe" [2008-06-18 268096] "KeyConfiguration"="c:\program files\Fujitsu Siemens Computers\Key Configuration Tool\KeyConfigurationTool.exe" [2008-09-04 413184] "Google EULA Launcher"="c:\program files\Google\Google EULA\GoogleEULALauncher.exe" [2008-05-28 20480] "ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-03-18 207360] "CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-10-25 652624] "CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-09-13 1603152] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-04 417792] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440] "Gigaget"="c:\program files\Giganology\Gigaget\GigagetShell.exe" [2006-02-07 495616] "Skytel"="Skytel.exe" [2008-08-27 1833504] "SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2009-10-20 111928] "hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016] "Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072] "AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe" [2010-05-07 344736] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552] "DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-09-01 1164584] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2008-02-26 443968] c:\users\Alex und Corinna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ FIFA 10-Registrierung.lnk - d:\fifa10\Support\EAregister.exe [2009-9-9 4374800] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) [hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler] "{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "c:\program files\Stardock\Fences\FencesMenu.dll" [2010-06-22 202088] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll c:\progra~1\KASPER~1\KASPER~1\mzvkbd3.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] SetupExecute REG_MULTI_SZ \0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 R1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [2010-05-06 132184] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 FSCLBaseUpdaterService;FSCLBaseUpdaterService;c:\program files\Fujitsu Siemens Computers\FSCLounge\FSCWBaseUpdaterService\2\FSCWBaseUpdaterService.exe [2007-06-04 65536] R2 gupdate1ca7694be04b671;Google Update Service (gupdate1ca7694be04b671);c:\program files\Google\Update\GoogleUpdate.exe [2009-12-06 133104] R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-08-01 30192] R3 netr28u;RT2870 USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr28u.sys [2008-07-31 641024] R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2009-09-04 3347280] R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2010-08-02 691696] S1 a2injectiondriver;a2injectiondriver;c:\program files\Emsisoft Anti-Malware\a2dix86.sys [2010-09-01 41816] S1 a2util;a-squared Malware-IDS utility driver;c:\program files\Emsisoft Anti-Malware\a2util32.sys [2010-05-05 11776] S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2010-04-22 22104] S2 a2AntiMalware;Emsisoft Anti-Malware 5.0 - Service;c:\program files\Emsisoft Anti-Malware\a2service.exe [2010-07-28 1935656] S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-21 21504] S2 MotoConnect Service;MotoConnect Service;c:\program files\Motorola\MotoConnectService\MotoConnectService.exe [2010-06-24 91456] S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] S2 TeamViewer5;TeamViewer 5;c:\program files\TeamViewer\Version5\TeamViewer_Service.exe [2010-01-12 185640] S2 TunngleService;TunngleService;c:\program files\Tunngle\TnglCtrl.exe [2010-09-14 716024] S3 a2acc;a2acc;c:\program files\EMSISOFT ANTI-MALWARE\a2accx86.sys [2010-06-28 71008] S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2009-11-02 19984] S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys [2009-09-16 27136] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] WindowsMobile REG_MULTI_SZ wcescomm rapimgr LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache Akamai REG_MULTI_SZ Akamai . Inhalt des "geplante Tasks" Ordners 2010-09-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-12-06 16:54] 2010-09-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-12-06 16:54] 2010-09-18 c:\windows\Tasks\ParetoLogic Registration.job - c:\program files\Common Files\ParetoLogic\UUS2\UUS.dll [2009-01-13 14:59] 2009-12-12 c:\windows\Tasks\ParetoLogic Update Version2.job - c:\program files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe [2009-01-13 14:59] 2010-09-18 c:\windows\Tasks\User_Feed_Synchronization-{FD9BE6BC-8F12-4671-89C2-5B865B98E93A}.job - c:\windows\system32\msfeedssync.exe [2010-08-13 04:24] . . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://search.orbitdownloader.com mStart Page = uInternet Settings,ProxyOverride = *.local IE: &Download All by Gigaget - c:\program files\Giganology\Gigaget\getallurl.htm IE: &Download by Gigaget - c:\program files\Giganology\Gigaget\geturl.htm IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 FF - ProfilePath - c:\users\Alex und Corinna\AppData\Roaming\Mozilla\Firefox\Profiles\mxpup8ml.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2447621&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - ICQ Search FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/ FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=skins7&tb_ver=2.0.0.2&q= FF - component: c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\kavlinkfilter.dll FF - component: c:\users\Alex und Corinna\AppData\Roaming\Mozilla\Firefox\Profiles\mxpup8ml.default\extensions\{ef468e5b-5b30-4136-a833-7f2e3a31afdf}\components\FFExternalAlert.dll FF - component: c:\users\Alex und Corinna\AppData\Roaming\Mozilla\Firefox\Profiles\mxpup8ml.default\extensions\{ef468e5b-5b30-4136-a833-7f2e3a31afdf}\components\RadioWMPCore.dll FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll FF - plugin: c:\program files\Picasa2\npPicasa3.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ---- FIREFOX Richtlinien ---- FF - user.js: network.cookie.cookieBehavior - 0 FF - user.js: privacy.clearOnShutdown.cookies - false FF - user.js: security.warn_viewing_mixed - false FF - user.js: security.warn_viewing_mixed.show_once - false FF - user.js: security.warn_submit_insecure - false FF - user.js: security.warn_submit_insecure.show_once - false c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false); . - - - - Entfernte verwaiste Registrierungseinträge - - - - WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) HKCU-Run-ICQ - ~c:\program files\ICQ7.2\ICQ.exe HKU-Default-Run-fsc-reg - c:\fsc-reg\fscreg.exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net Rootkit scan 2010-09-19 14:10 Windows 6.0.6002 Service Pack 2 NTFS detected NTDLL code modification: ZwOpenFile Scanne versteckte Prozesse... Scanne versteckte Autostarteinträge... Scanne versteckte Dateien... Scan erfolgreich abgeschlossen versteckte Dateien: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . --------------------- Gesperrte Registrierungsschluessel --------------------- [HKEY_USERS\S-1-5-21-3007487369-405977050-4058923890-1000\Software\SecuROM\License information*] "datasecu"=hex:a4,4c,28,87,3d,53,72,9c,c8,08,2c,34,4d,0e,69,88,74,6b,4b,94,9d, d0,6b,73,4e,9c,52,7f,27,26,e7,96,c6,ef,cd,ce,76,e8,ce,2c,49,dc,41,a1,13,61,\ "rkeysecu"=hex:44,c8,b9,9f,32,57,3b,cb,d1,4b,2e,c3,b7,6d,88,b1 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . ------------------------ Weitere laufende Prozesse ------------------------ . c:\windows\system32\nvvsvc.exe c:\windows\system32\rundll32.exe c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Canon\IJPLM\IJPLMSVC.EXE c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe c:\windows\system32\IoctlSvc.exe c:\windows\system32\PnkBstrA.exe c:\windows\system32\PnkBstrB.exe c:\program files\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe c:\windows\system32\WUDFHost.exe c:\windows\System32\rundll32.exe c:\windows\RtHDVCpl.exe c:\windows\system32\wbem\unsecapp.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\program files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac c:\windows\ehome\ehmsas.exe c:\program files\iPod\bin\iPodService.exe c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe c:\program files\Motorola\MotoConnectService\MotoConnect.exe c:\windows\servicing\TrustedInstaller.exe . ************************************************************************** . Zeit der Fertigstellung: 2010-09-19 14:18:01 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2010-09-19 12:17 Vor Suchlauf: 25 Verzeichnis(se), 10.946.310.144 Bytes frei Nach Suchlauf: 29 Verzeichnis(se), 11.395.776.512 Bytes frei Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4 - - End Of File - - 107F9C96ABF4BB775089D84CD8EF0A5F mfg DDDAlexDDD |
Themen zu Backdoorporgramm Problem! |
antivirenprogramm, beim starten, das angegebene modul wurde nicht gefunden, entdeck, fehler, folge, frage, fragen, gelöscht, hallo zusammen, home, home premium, laden, langsamer, löschen, modul, nicht gefunden, problem, seltsame, starten, tipps, total, vista, vista home premium, windows, windows vista, windows vista home, zugriff, zugriff verweigert |