Combofix Logfile:
Code:
Alles auswählen Aufklappen ATTFilter
ComboFix 11-06-01.01 - XXXXXX 01.06.2011 17:25:27.1.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.49.1031.18.1790.925 [GMT 2:00]
ausgeführt von:: c:\users\XXXXX\Desktop\cofi.exe
AV: ESET Smart Security 4.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET Personal Firewall *Enabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 4.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Andre\AppData\Roaming\ezpinst.log
.
.
((((((((((((((((((((((( Dateien erstellt von 2011-05-01 bis 2011-06-01 ))))))))))))))))))))))))))))))
.
.
2011-06-01 15:34 . 2011-06-01 15:37 -------- d-----w- c:\users\Andre\AppData\Local\temp
2011-06-01 15:34 . 2011-06-01 15:34 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-06-01 11:34 . 2011-06-01 11:34 -------- d-----w- C:\_OTL
2011-05-31 22:16 . 2011-05-09 20:46 6962000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FAC056A6-013F-4C92-A132-3355708690F5}\mpengine.dll
2011-05-31 20:21 . 2010-12-20 16:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-31 20:21 . 2011-05-31 20:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-05-31 20:21 . 2010-12-20 16:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-05-21 20:11 . 2004-10-13 12:28 505104 ----a-w- c:\windows\system32\msxml.dll
2011-05-21 20:11 . 2004-10-13 12:28 115016 ----a-w- c:\windows\system32\MSINET.OCX
2011-05-21 20:11 . 2011-05-21 20:11 -------- d-----w- c:\program files\Ubisoft
2011-05-21 20:11 . 2004-10-13 12:28 69632 ----a-w- c:\windows\system32\xmltok.dll
2011-05-21 20:11 . 2004-10-13 12:28 36864 ----a-w- c:\windows\system32\xmlparse.dll
2011-05-21 20:11 . 2004-10-13 12:28 89360 ----a-w- c:\windows\system32\VB5DB.DLL
2011-05-21 20:11 . 2004-10-13 12:28 35840 ----a-w- c:\windows\system32\comdlg32.oca
2011-05-21 20:11 . 2004-10-13 12:28 29184 ----a-w- c:\windows\system32\MSINET.oca
2011-05-21 20:11 . 2004-10-13 12:28 28432 ----a-w- c:\windows\system32\msxmlr.dll
2011-05-21 20:11 . 2004-10-13 12:28 26096 ----a-w- c:\windows\system32\xmlinst.exe
2011-05-21 20:11 . 2004-10-13 12:28 24576 ----a-w- c:\windows\system32\msxml3a.dll
2011-05-21 20:03 . 2004-10-22 00:18 749568 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iKernel.dll
2011-05-21 20:03 . 2004-10-22 00:17 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\ctor.dll
2011-05-21 20:03 . 2004-10-22 00:17 274432 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iscript.dll
2011-05-21 20:03 . 2004-10-22 00:16 180224 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iuser.dll
2011-05-21 20:03 . 2004-10-22 00:16 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\DotNetInstaller.exe
2011-05-15 21:24 . 2011-05-15 21:33 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-05-15 21:24 . 2011-05-15 21:25 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-05-15 20:55 . 2011-05-15 20:55 -------- d-----w- c:\program files\CCleaner
2011-05-15 20:44 . 2011-04-09 05:56 123904 ----a-w- c:\windows\system32\poqexec.exe
2011-05-15 16:17 . 2011-05-15 16:17 -------- d-----w- c:\program files\Common Files\Java
2011-05-11 15:52 . 2011-05-11 16:05 -------- d-----w- c:\program files\ICQ7.5
2011-05-11 12:05 . 2011-04-09 06:13 3957632 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-05-11 12:05 . 2011-04-09 06:13 3901824 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-05-08 18:22 . 2011-05-08 18:22 89048 ----a-w- c:\program files\Mozilla Firefox\libEGL.dll
2011-05-08 18:22 . 2011-05-08 18:22 781272 ----a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2011-05-08 18:22 . 2011-05-08 18:22 465880 ----a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2011-05-08 18:22 . 2011-05-08 18:22 1874904 ----a-w- c:\program files\Mozilla Firefox\mozjs.dll
2011-05-08 18:22 . 2011-05-08 18:22 15832 ----a-w- c:\program files\Mozilla Firefox\mozalloc.dll
2011-05-08 18:22 . 2011-05-08 18:22 1892184 ----a-w- c:\program files\Mozilla Firefox\d3dx9_42.dll
2011-05-08 18:22 . 2011-05-08 18:22 142296 ----a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-05-08 18:22 . 2011-05-08 18:22 1974616 ----a-w- c:\program files\Mozilla Firefox\D3DCompiler_42.dll
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-24 17:14 . 2009-10-14 02:21 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-04-14 03:07 . 2010-07-18 15:57 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-04-08 11:28 . 2011-04-08 11:28 41872 ----a-w- c:\windows\system32\xfcodec.dll
2011-03-11 05:40 . 2011-04-13 15:38 1164288 ----a-w- c:\windows\system32\mfc42u.dll
2011-03-11 05:40 . 2011-04-13 15:38 1137664 ----a-w- c:\windows\system32\mfc42.dll
2011-03-08 05:38 . 2011-04-13 15:39 740864 ----a-w- c:\windows\system32\inetcomm.dll
2011-05-08 18:22 . 2011-05-08 18:22 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2006-05-03 10:06 163328 --sh--r- c:\windows\System32\flvDX.dll
2007-02-21 11:47 31232 --sh--r- c:\windows\System32\msfDX.dll
2008-03-16 13:30 216064 --sh--r- c:\windows\System32\nbDX.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
"ICQ"="c:\program files\ICQ7.4\ICQ.exe" [2011-04-23 119608]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-01-07 253672]
"Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2009-04-10 1833504]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-04-10 7399968]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-08-10 421888]
"PLFSetI"="c:\windows\PLFSetI.exe" [2008-07-29 200704]
"Launch SilverCrest GML807"="c:\program files\SilverCrest GML807 Driver\MouClient_FD2_1001RL.exe" [2010-09-02 862208]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-01 421160]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-01-12 2219184]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKLM\~\startupfolder\C:^Users^Andre^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^CurseClientStartup.ccip]
path=c:\users\Andre\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip
backup=c:\windows\pss\CurseClientStartup.ccip.Startup
backupExtension=.Startup
.
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~1\mcafee\SITEAD~1\McSACore.exe [2011-02-16 88176]
R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x]
R3 FlashUSB;FlashUSB;c:\windows\system32\DRIVERS\FlashUSB.sys [2009-05-12 16896]
R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2009-07-20 116136]
R3 massfilter;Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [x]
R4 MSSQLServerADHelper100;SQL Server Hilfsdienst für Active Directory;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2008-07-11 47128]
R4 RsFx0102;RsFx0102 Driver;c:\windows\system32\DRIVERS\RsFx0102.sys [2008-07-10 242712]
R4 SQLAgent$SQLEXPRESS;SQL Server-Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2008-07-11 369688]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-02-03 218688]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-12-21 115008]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 176128]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-12-21 137144]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2011-01-12 810144]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2010-12-21 41336]
S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [2008-04-29 54784]
S3 InputFilter_Hid_FlexDef2c;Siliten HID Devices(FlexDef2c) Driver Service;c:\windows\system32\DRIVERS\InputFilter_FlexDef2c.sys [2010-08-06 16896]
S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360]
S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992]
S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2009-04-03 27320]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - 97452831
*Deregistered* - 97452831
.
.
------- Zusätzlicher Suchlauf -------
.
uInternet Settings,ProxyOverride = *.local
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\Andre\AppData\Roaming\Mozilla\Firefox\Profiles\k2veblcu.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
FF - prefs.js: keyword.URL - hxxp://de.search.yahoo.com/search?fr=mcafee&p=
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2011-06-01 17:39:44
ComboFix-quarantined-files.txt 2011-06-01 15:39
.
Vor Suchlauf: 13 Verzeichnis(se), 17.338.773.504 Bytes frei
Nach Suchlauf: 19 Verzeichnis(se), 17.161.871.360 Bytes frei
.
- - End Of File - - 31A01DE6D8A46E1A8D76055F4EB68353
--- --- ---