Hier die Log-Datei von Combofix: Code:
ComboFix 12-06-21.01 - *** 21.06.2012 12:48:26.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.3070.1866 [GMT 2:00]
ausgeführt von:: c:\users\***\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\program files\Common Files\ASPG_icon.ico
c:\program files\Common Files\Tencent\Paycenter
c:\program files\Common Files\Tencent\Paycenter\qqcert.dll
c:\program files\Common Files\Tencent\Paycenter\qqedit.dll
c:\program files\TENCENT\SSPlus\SData.dat
c:\program files\TENCENT\SSPlus\SPlus.dll
c:\program files\TENCENT\SSPlus\stdtbh.dat
c:\users\***\AppData\Roaming\7za.exe
c:\users\***\AppData\Roaming\a.7z
c:\users\***\AppData\Roaming\Google\Update\1
c:\users\***\AppData\Roaming\Google\Update\1\SD\m.txt
c:\users\***\AppData\Roaming\Google\Update\1\SD\s.txt
c:\users\***\AppData\Roaming\Mac\MacJie.key
c:\users\***\AppData\Roaming\SogouExplorer
c:\users\***\AppData\Roaming\SogouExplorer\abw
c:\users\***\AppData\Roaming\SogouExplorer\adbdata.dat
c:\users\***\AppData\Roaming\SogouExplorer\CommCfg.xml
c:\users\***\AppData\Roaming\SogouExplorer\confdll.dll
c:\users\***\AppData\Roaming\SogouExplorer\Config.xml
c:\users\***\AppData\Roaming\SogouExplorer\configlocal.xml
c:\users\***\AppData\Roaming\SogouExplorer\DailyBackup\Favorite2.dat.2010.08.19.16
c:\users\***\AppData\Roaming\SogouExplorer\DailyBackup\Favorite2.dat.2010.11.13.11
c:\users\***\AppData\Roaming\SogouExplorer\DailyBackup\Favorite2.dat.2010.11.17.18
c:\users\***\AppData\Roaming\SogouExplorer\DailyBackup\Favorite2.dat.2010.11.20.11
c:\users\***\AppData\Roaming\SogouExplorer\DailyBackup\Favorite2.dat.2011.03.03.04
c:\users\***\AppData\Roaming\SogouExplorer\DailyBackup\Favorite2.dat.2011.08.04.20
c:\users\***\AppData\Roaming\SogouExplorer\dew
c:\users\***\AppData\Roaming\SogouExplorer\FavIcon\default_page.ico
c:\users\***\AppData\Roaming\SogouExplorer\FavIcon\http_ie.sogou.com_80_fav.ico
c:\users\***\AppData\Roaming\SogouExplorer\FavIcon\http_pinyin.sogou.com_80_fav.ico
c:\users\***\AppData\Roaming\SogouExplorer\FavIcon\http_pralerts.zonealarm.com_80_fav.ico
c:\users\***\AppData\Roaming\SogouExplorer\FavIcon\http_www.ceruleanstudios.com_80_fav.ico
c:\users\***\AppData\Roaming\SogouExplorer\FavIcon\http_www.icq.com_80_fav.ico
c:\users\***\AppData\Roaming\SogouExplorer\FavIcon\http_www.trillian.im_80_fav.ico
c:\users\***\AppData\Roaming\SogouExplorer\FavIcon\https_www3.gotowebinar.com_443_fav.ico
c:\users\***\AppData\Roaming\SogouExplorer\Favorite2.dat
c:\users\***\AppData\Roaming\SogouExplorer\FormData.dat
c:\users\***\AppData\Roaming\SogouExplorer\HistoryUrl.db
c:\users\***\AppData\Roaming\SogouExplorer\MCPattern.db
c:\users\***\AppData\Roaming\SogouExplorer\Misc.db
c:\users\***\AppData\Roaming\SogouExplorer\Openpage.xml
c:\users\***\AppData\Roaming\SogouExplorer\playevent.pat
c:\users\***\AppData\Roaming\SogouExplorer\se_setup.ini
c:\users\***\AppData\Roaming\SogouExplorer\SEacc_F5_pattern.txt
c:\users\***\AppData\Roaming\SogouExplorer\SEacc_refresh_pattern.txt
c:\users\***\AppData\Roaming\SogouExplorer\sodaliblite.dll
c:\users\***\AppData\Roaming\SogouExplorer\SogouExplorerSetup.exe
c:\users\***\AppData\Roaming\SogouExplorer\uhistory.db
c:\users\***\AppData\Roaming\SogouExplorer\UserId.enc
c:\users\***\AppData\Roaming\SogouExplorer\videopattern
c:\users\***\AppData\Roaming\SogouExplorer\Webkit\Cache\data_0
c:\users\***\AppData\Roaming\SogouExplorer\Webkit\Cache\data_1
c:\users\***\AppData\Roaming\SogouExplorer\Webkit\Cache\data_2
c:\users\***\AppData\Roaming\SogouExplorer\Webkit\Cache\data_3
c:\users\***\AppData\Roaming\SogouExplorer\Webkit\Cache\f_000001
c:\users\***\AppData\Roaming\SogouExplorer\Webkit\Cache\f_000002
c:\users\***\AppData\Roaming\SogouExplorer\Webkit\Cache\f_000003
c:\users\***\AppData\Roaming\SogouExplorer\Webkit\Cache\f_000004
c:\users\***\AppData\Roaming\SogouExplorer\Webkit\Cache\index
c:\users\***\AppData\Roaming\SogouExplorer\Webkit\Cookies
c:\users\***\AppData\Roaming\SogouExplorer\Webkit\VisitedLinks
c:\windows\IsUn0407.exe
c:\windows\PFRO.log
c:\windows\system32\drivers\~GLH0014.TMP
.
.
((((((((((((((((((((((( Dateien erstellt von 2012-05-21 bis 2012-06-21 ))))))))))))))))))))))))))))))
.
.
2012-06-21 10:30 . 2012-06-02 22:19 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-21 10:30 . 2012-06-02 22:19 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-21 10:30 . 2012-06-02 22:19 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-21 10:30 . 2012-06-02 22:12 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-06-21 10:29 . 2012-06-02 22:19 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-21 10:29 . 2012-06-02 22:19 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-21 10:29 . 2012-06-02 22:12 88576 ----a-w- c:\windows\system32\wudriver.dll
2012-06-21 10:29 . 2012-06-02 13:19 171904 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-21 10:29 . 2012-06-02 13:12 33792 ----a-w- c:\windows\system32\wuapp.exe
2012-06-19 23:24 . 2012-02-29 15:11 5120 ----a-w- c:\windows\system32\wmi.dll
2012-06-19 23:24 . 2012-02-29 15:11 172032 ----a-w- c:\windows\system32\wintrust.dll
2012-06-19 23:24 . 2012-02-29 15:09 157696 ----a-w- c:\windows\system32\imagehlp.dll
2012-06-19 23:24 . 2012-02-29 13:32 12800 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-06-19 18:49 . 2012-06-19 18:49 -------- d-----w- c:\program files\Microsoft Chart Controls
2012-06-19 14:17 . 2012-06-19 14:17 -------- d-----w- C:\fe83392acf11f46d51bad2caf9119a
2012-06-19 14:07 . 2012-06-19 14:07 98816 ----a-w- c:\windows\system32\mfps.dll
2012-06-19 13:52 . 2011-11-18 17:47 66560 ----a-w- c:\windows\system32\packager.dll
2012-06-19 13:51 . 2010-12-17 15:45 2067968 ----a-w- c:\windows\system32\mstscax.dll
2012-06-19 13:51 . 2010-12-17 13:54 677888 ----a-w- c:\windows\system32\mstsc.exe
2012-06-19 13:48 . 2011-09-30 15:57 707584 ----a-w- c:\program files\Common Files\System\wab32.dll
2012-06-19 13:48 . 2012-04-03 08:16 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-06-19 13:48 . 2012-04-03 08:16 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-06-19 13:45 . 2011-04-21 13:55 508416 ----a-w- c:\windows\system32\drivers\bthport.sys
2012-06-19 10:30 . 2012-06-19 10:30 -------- d-----w- C:\_OTL
2012-06-17 12:20 . 2012-06-17 12:20 0 ----a-w- c:\windows\system32\nsd8756.tmp
2012-06-16 12:18 . 2012-06-16 12:18 -------- d-----w- c:\program files\ESET
2012-06-14 14:43 . 2012-06-14 14:49 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2012-06-14 14:43 . 2012-06-14 14:45 -------- d-----w- c:\program files\Spybot - Search & Destroy
2012-06-14 10:33 . 2012-06-14 10:33 -------- d-----w- c:\users\***\AppData\Roaming\Malwarebytes
2012-06-14 10:33 . 2012-06-14 10:33 -------- d-----w- c:\programdata\Malwarebytes
2012-06-14 10:33 . 2012-06-14 10:33 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-06-14 10:33 . 2012-04-04 13:56 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-06-08 07:21 . 2012-06-08 07:21 2991512 ----a-w- c:\windows\system32\SogouPY.ime
2012-05-22 16:19 . 2012-06-20 18:04 -------- d-----w- c:\program files\Diablo III
2012-05-22 16:19 . 2012-05-22 16:44 -------- d-----w- c:\programdata\Blizzard Entertainment
2012-05-22 16:19 . 2012-05-22 16:44 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2012-05-22 16:13 . 2012-05-22 16:13 -------- d-----w- c:\programdata\Battle.net
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-21 12:07 . 2009-07-10 17:35 45056 ----a-w- c:\windows\system32\acovcnt.exe
2012-06-20 22:03 . 2009-07-11 17:51 140304 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-06-20 22:03 . 2009-07-11 19:01 281032 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-06-20 22:03 . 2009-07-11 17:51 281032 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-06-20 18:35 . 2009-07-11 17:51 281032 ----a-w- c:\windows\system32\PnkBstrB.ex0
2012-06-19 18:43 . 2009-07-11 17:51 138056 ----a-w- c:\users\***\AppData\Roaming\PnkBstrK.sys
2012-06-19 18:43 . 2009-07-11 17:50 76888 ----a-w- c:\windows\system32\PnkBstrA.exe
2012-05-09 14:55 . 2011-10-16 13:24 83392 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2012-05-09 14:55 . 2011-10-16 13:24 137928 ----a-w- c:\windows\system32\drivers\avipbb.sys
2012-04-01 13:28 . 2012-04-01 13:28 19352 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2008-08-08 22:48 . 2008-08-08 22:48 90112 ----a-w- c:\program files\Common Files\CPInstallAction.dll
2012-05-06 10:58 . 2011-05-15 17:12 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2009-05-04 05:14 . 2009-10-11 18:17 36864 ----a-w- c:\program files\mozilla firefox\components\NsThunderLoader.dll
2009-05-04 05:14 . 2009-10-11 18:17 53248 ----a-w- c:\program files\mozilla firefox\components\ThunderComponent.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-02 01:08 143360 ----a-w- c:\program files\ASUS\ASUS Data Security Manager\OverlayIconShlExt1.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ----a-w- c:\users\***\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ----a-w- c:\users\***\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ----a-w- c:\users\***\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ----a-w- c:\users\***\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-02-28 1828136]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2010-09-12 2969496]
"Dexpot"="c:\program files\Dexpot\dexpot.exe" [2011-11-22 1425408]
"Duden Korrektor SysTray"="c:\program files\Duden\Duden-Rechtschreibprüfung\DKTray.exe" [2011-07-14 332432]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"P2Go_Menu"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"HControlUser"="c:\program files\ASUS\ATK Hotkey\HControlUser.exe" [2008-08-18 98304]
"ATKOSD2"="c:\program files\ASUS\ATKOSD2\ATKOSD2.exe" [2008-09-03 8105984]
"RtHDVCpl"="RtHDVCpl.exe" [2008-08-12 6265376]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-06 1029416]
"DirectConsole2"="c:\program files\ASUS\Direct Console\Direct Console.exe" [2008-08-21 2705976]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 56080]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-18 2221352]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2007-02-17 1194728]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2007-02-17 1966928]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2007-02-16 149024]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-08-19 13793824]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2011-01-22 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-09-16 1164584]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-05-09 348624]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-09-30 252296]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Duden Korrektor SysTray"="c:\program files\Duden\Duden-Rechtschreibprüfung\DKTray.exe" [2011-07-14 332432]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
SetPoint.lnk - c:\program files\SetPoint\SetPoint.exe [2008-12-5 692224]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi9"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e0200804]
Ime File REG_SZ SOGOUPY.IME
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
backup=c:\windows\pss\Bluetooth.lnk.CommonStartup
backupExtension=.CommonStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerForPhone
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-01-22 05:05 40368 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer]
2008-07-19 03:52 104936 ----a-w- c:\program files\CyberLink\Power2Go\CLMLSvc.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2008-06-09 18:16 2363392 ----a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2009-08-19 07:24 13793824 ----a-w- c:\windows\System32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2009-08-19 07:24 92704 ----a-w- c:\windows\System32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-21 02:23 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\6de2ed6f-0b56-4d57-b0f0-551ec8cbb27f]
2011-07-01 09:38 153232 ---ha-w- c:\programdata\Duden\DKReg.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 18:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Inhalt des "geplante Tasks" Ordners
.
2012-06-21 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-04 15:03]
.
2012-06-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-04 15:04]
.
2012-06-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-04 15:04]
.
2012-06-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1799299016-3692624258-2031827036-1000Core.job
- c:\users\***\AppData\Local\Google\Update\GoogleUpdate.exe [2011-09-13 15:48]
.
2012-06-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1799299016-3692624258-2031827036-1000UA.job
- c:\users\***\AppData\Local\Google\Update\GoogleUpdate.exe [2011-09-13 15:48]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = about:blank
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=ASUS&bmod=ASUS
uInternet Settings,ProxyOverride = local;*.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Download with Xilisoft Download YouTube Video - c:\program files\Xilisoft\Download YouTube Video\upod_link.HTM
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Free YouTube Download - c:\users\***\AppData\Roaming\DVDVideoSoftIEHelpers\youtubedownload.htm
IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{09BA8F6D-CB54-424B-839C-C2A6C8E6B436}
IE: {{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - c:\program files\ICQ7.4\ICQ.exe
Trusted Zone: alipay.com
Trusted Zone: alisoft.com
Trusted Zone: taobao.com
Trusted Zone: qq.com\cache.tv
Trusted Zone: qq.com\qqlivecaption
Trusted Zone: qq.com\qqlivehabit
Trusted Zone: qq.com\qqlivesearch
Trusted Zone: qq.com\video_1
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\***\AppData\Roaming\Mozilla\Firefox\Profiles\3hp8zgmd.default\
FF - prefs.js: browser.search.selectedEngine - Wikipedia (de)
FF - prefs.js: network.proxy.http - 114.32.112.213
FF - prefs.js: network.proxy.http_port - 3128
FF - prefs.js: network.proxy.type - 0
.
.
------- Dateityp-Verknüpfung -------
.
txtfile=c:\windows\notepad.exe %1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKCU-Run-Akamai NetSession Interface - c:\users\***\AppData\Local\Akamai\netsession_win.exe
HKCU-Run-Google - c:\users\***\AppData\Roaming\googleoez.exe
AddRemove-Command & Conquer - d:\spiele\CnC\Uninstal.exe
AddRemove-ESET Online Scanner - c:\program files\ESET\ESET Online Scanner\OnlineScannerUninstaller.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2012-06-21 14:08
Windows 6.0.6002 Service Pack 2 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
.
C:\ADSM_PData_0150
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 1
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1799299016-3692624258-2031827036-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:45,ca,61,db,8e,38,ba,2e,41,da,d4,d3,f0,4e,f2,d0,e0,eb,24,0f,e7,29,1a,
30,8b,a8,62,b5,c7,15,14,c9,68,c1,e0,64,1c,46,90,b7,b5,d5,94,07,33,cb,fc,10,\
"??"=hex:3e,f2,b3,06,b5,62,1f,ca,97,78,ed,73,a0,8c,5f,4d
.
[HKEY_USERS\S-1-5-21-1799299016-3692624258-2031827036-1000\Software\SecuROM\License information*]
"datasecu"=hex:95,55,66,54,ae,a3,0c,53,72,e2,6e,21,10,53,b3,da,ca,c1,9a,5d,1d,
9f,74,10,f8,9a,58,03,43,3e,bd,ea,0f,24,d7,be,00,08,18,84,19,2d,1a,09,cb,f7,\
"rkeysecu"=hex:ae,76,d6,ff,5c,aa,c1,e8,dd,b6,31,1e,eb,bc,d0,71
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{0494ed2b-a00c-406c-a62f-21ebc82e1186}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:2a000000
"Dhcpv6State"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{199d9774-1d87-43c0-bcef-811959e175fd}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:0a002354
"Dhcpv6State"=dword:00000000
"NameServer"=""
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{214985cb-91b5-4edb-bf49-04603d706110}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:26002243
"Dhcpv6State"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{33420e29-6319-49a4-b419-f73ef867e746}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:0f001e8c
"Dhcpv6State"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{524e379e-e44e-48f3-bcc2-88d51e6e642f}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:24000000
"Dhcpv6State"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{98595871-6298-4994-88cc-750eae58c6e5}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:1c000000
"Dhcpv6State"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{9c642153-bfe0-4511-a0b6-e778ddd5ea9e}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:07001422
"Dhcpv6State"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{ac27e35c-a17d-4f60-be78-eb644acff10d}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:10002354
"Dhcpv6State"=dword:00000001
"NameServer"=""
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{b040e30f-1320-4b9c-aeb9-c4a1e75acbdd}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:29000000
"Dhcpv6State"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{ba32a50a-3d27-4fae-8591-5916311409be}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:0c001422
"Dhcpv6State"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{c3ff4a6b-afd8-4b3b-b55b-de46eadd3bd9}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:1100215d
"Dhcpv6State"=dword:00000000
"NameServer"=""
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{e0a5b4ad-2971-4d2c-9730-425ce6b065a4}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:14020054
"Dhcpv6State"=dword:00000000
"NameServer"=""
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{e3956ff0-3f9f-4edc-b5e3-0fbfac891c85}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:277a7700
"Dhcpv6State"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{ed7eb904-6721-47cc-a022-f7788a4a5638}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:0c002243
"Dhcpv6State"=dword:00000000
"NameServer"=""
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{ee935c63-a647-4d71-b1eb-b2cb7135d8d9}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:217a7991
"Dhcpv6State"=dword:00000001
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{f50c0996-5b4a-4c6a-a322-6e991d4caa0e}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:06001422
"Dhcpv6State"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{f70a361f-6437-4fcc-91a4-cd88d468d91b}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:0e001422
"Dhcpv6State"=dword:00000000
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'lsass.exe'(1008)
c:\windows\system32\relog_ap.dll
.
- - - - - - - > 'Explorer.exe'(4524)
c:\program files\Dexpot\hooxpot.dll
c:\program files\SetPoint\GameHook.dll
c:\program files\SetPoint\lgscroll.dll
c:\program files\ASUS\ASUS Data Security Manager\OverlayIconShlExt.dll
c:\program files\ASUS\ASUS Data Security Manager\OverlayIconShlExt1.dll
c:\users\***\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\nvvsvc.exe
c:\program files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
c:\program files\ASUS\ATK Hotkey\ASLDRSrv.exe
c:\program files\ATKGFNEX\GFNEXSrv.exe
c:\program files\Avira\AntiVir Desktop\sched.exe
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\IoctlSvc.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\ASUS\NB Probe\SPM\spmgr.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\Spybot - Search & Destroy\SDWinSec.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe
c:\program files\ASUS\SmartLogon\sensorsrv.exe
c:\program files\ASUS\ASUS CopyProtect\aspg.exe
c:\program files\ASUS\ATK Hotkey\MsgTranAgt.exe
c:\program files\ASUS\ATK Hotkey\HControl.exe
c:\program files\P4G\BatteryLife.exe
c:\program files\ASUS\Splendid\ACMON.exe
c:\windows\System32\ACEngSvr.exe
c:\program files\ASUS\ATK Hotkey\ATKOSD.exe
c:\program files\ASUS\ATK Hotkey\KBFiltr.exe
c:\program files\ASUS\ATK Hotkey\WDC.exe
c:\windows\RtHDVCpl.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Synaptics\SynTP\SynTPHelper.exe
c:\program files\Common Files\Nero\Lib\NMIndexingService.exe
c:\program files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
c:\program files\Windows Mail\WinMail.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-06-21 14:20:09 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2012-06-21 12:19
.
Vor Suchlauf: 16 Verzeichnis(se), 34.484.191.232 Bytes frei
Nach Suchlauf: 22 Verzeichnis(se), 36.857.126.912 Bytes frei
.
- - End Of File - - 56DBC4D0925505FD4C13B816650ACAC2 |