Hier is der log Code:
ComboFix 13-05-31.02 - Kinder 31.05.2013 18:07:09.1.4 - x86
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.49.1031.18.2935.1636 [GMT 2:00]
ausgeführt von:: c:\users\Kinder\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}
SP: Microsoft Security Essentials *Disabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\intellidownload\gunzip.exe
c:\program files\intellidownload\search.exe
c:\program files\PricePeep
c:\program files\PricePeep\installer.ico
c:\program files\PricePeep\pricepeep.crx
c:\program files\PricePeep\uninstall.exe
c:\program files\SSearch
c:\program files\SSearch\sqlite3.exe
c:\program files\Windows Live\Messenger\msacm32.dll
c:\users\Heidi\AppData\Roaming\.#
c:\users\Kinder\AppData\Roaming\.#
c:\windows\IsUn0407.exe
c:\windows\system32\tmp1111.tmp
c:\windows\system32\tmp1391.tmp
c:\windows\system32\tmpD29.tmp
c:\windows\system32\tmpD2A.tmp
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\regtlib.exe
c:\windows\unin0407.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-04-28 bis 2013-05-31 ))))))))))))))))))))))))))))))
.
.
2013-05-31 16:22 . 2013-05-31 16:22 -------- d-----w- c:\users\Heidi\AppData\Local\temp
2013-05-31 16:22 . 2013-05-31 16:23 -------- d-----w- c:\users\Kinder\AppData\Local\temp
2013-05-31 16:22 . 2013-05-31 16:22 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-05-31 15:56 . 2013-05-31 15:56 9310 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TEXTBOX.JS
2013-05-31 15:56 . 2013-05-31 15:56 8646 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TILEBOX.JS
2013-05-31 15:56 . 2013-05-31 15:56 6429 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UICORE.JS
2013-05-31 15:56 . 2013-05-31 15:56 63115 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\USERTILE.JS
2013-05-31 15:56 . 2013-05-31 15:56 4599 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UIRESOURCE.JS
2013-05-31 15:55 . 2013-05-31 15:55 8613 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\SAVEDUSER.JS
2013-05-31 15:55 . 2013-05-31 15:55 8288 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\IMAGE.JS
2013-05-31 15:55 . 2013-05-31 15:55 6910 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\NEWUSERCOMM.JS
2013-05-31 15:55 . 2013-05-31 15:55 6208 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\LINK.JS
2013-05-31 15:55 . 2013-05-31 15:55 5927 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TEXT.JS
2013-05-31 15:55 . 2013-05-31 15:55 18541 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\LOCALIZATION.JS
2013-05-31 15:55 . 2013-05-31 15:55 1651 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\QUERYSTRING.JS
2013-05-31 15:55 . 2013-05-31 15:55 8782 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\BUTTON.JS
2013-05-31 15:55 . 2013-05-31 15:55 7271 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\CHECKBOX.JS
2013-05-31 15:55 . 2013-05-31 15:55 51852 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\EXTERNALWRAPPER.JS
2013-05-31 15:55 . 2013-05-31 15:55 23327 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\COMBOBOX.JS
2013-05-31 15:55 . 2013-05-31 15:55 20719 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\DIVWRAPPER.JS
2013-05-31 13:07 . 2013-05-31 13:07 -------- d-----w- c:\windows\system32\SPReview
2013-05-31 12:39 . 2013-05-31 12:39 -------- d-----w- C:\FRST
2013-05-28 10:43 . 2013-05-13 06:19 7016152 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{22E6E13A-24DC-4A61-8D19-315C47773716}\mpengine.dll
2013-05-27 19:28 . 2013-05-27 19:28 -------- d-----w- c:\users\Kinder\AppData\Roaming\Malwarebytes
2013-05-27 19:27 . 2013-05-27 19:27 -------- d-----w- c:\programdata\Malwarebytes
2013-05-27 19:27 . 2013-05-27 19:28 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-05-27 19:27 . 2013-04-04 12:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-05-27 19:27 . 2013-05-27 19:27 -------- d-----w- c:\users\Kinder\AppData\Local\Programs
2013-05-27 01:30 . 2013-05-13 06:19 7016152 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-05-24 12:34 . 2013-05-24 12:33 724464 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BC4CFCF5-9216-4241-BF71-23415C8AAFF0}\gapaengine.dll
2013-05-19 08:27 . 2013-05-19 08:27 -------- d-----w- C:\Mozilla
2013-05-10 07:57 . 2013-05-10 07:57 187456 ----a-w- c:\program files\Internet Explorer\plugins\nppdf32.dll
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-05-27 20:29 . 2012-02-02 19:06 164880 ---ha-w- c:\users\Kinder\AppData\Roaming\Microsoft\Virtual PC\VPCKeyboard.dll
2013-05-17 15:27 . 2013-03-07 19:22 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-05-17 15:27 . 2011-05-17 07:25 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-05-02 15:28 . 2010-04-22 11:13 238872 ------w- c:\windows\system32\MpSigStub.exe
2013-04-24 15:48 . 2011-03-25 07:22 706640 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2013-04-12 13:58 . 2013-04-24 05:00 1210728 ----a-w- c:\windows\system32\drivers\ntfs.sys
2013-03-19 05:06 . 2013-04-10 15:50 3958120 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-03-19 05:06 . 2013-04-10 15:50 3902312 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-03-19 04:54 . 2013-04-10 15:50 38912 ----a-w- c:\windows\system32\csrsrv.dll
2013-03-19 02:50 . 2013-04-10 15:50 69632 ----a-w- c:\windows\system32\smss.exe
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2013-01-28 1520776]
"{f4e6547e-325b-403c-a3bb-ad29ed37a92f}"= "c:\program files\SearchElf_1.2\prxtbSea0.dll" [2013-04-14 231712]
.
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
.
[HKEY_CLASSES_ROOT\clsid\{f4e6547e-325b-403c-a3bb-ad29ed37a92f}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{F1AF26F8-1828-4279-ABCE-074EF3235BD7}]
2012-11-15 17:30 244328 ----a-w- c:\program files\SockshareDownloader\smarterdownloader.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{f4e6547e-325b-403c-a3bb-ad29ed37a92f}]
2013-04-14 12:35 231712 ----a-w- c:\program files\SearchElf_1.2\prxtbSea0.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{f4e6547e-325b-403c-a3bb-ad29ed37a92f}"= "c:\program files\SearchElf_1.2\prxtbSea0.dll" [2013-04-14 231712]
.
[HKEY_CLASSES_ROOT\clsid\{f4e6547e-325b-403c-a3bb-ad29ed37a92f}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{F4E6547E-325B-403C-A3BB-AD29ED37A92F}"= "c:\program files\SearchElf_1.2\prxtbSea0.dll" [2013-04-14 231712]
.
[HKEY_CLASSES_ROOT\clsid\{f4e6547e-325b-403c-a3bb-ad29ed37a92f}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-04-06 8555040]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RtHDVBg.exe" [2010-04-06 694816]
"HotkeyApp"="c:\program files\Launch Manager\HotkeyApp.exe" [2009-12-14 200704]
"LMgrVolOSD"="c:\program files\Launch Manager\OSD.exe" [2009-12-11 348960]
"Wbutton"="c:\program files\Launch Manager\Wbutton.exe" [2010-01-13 413696]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-12-11 1594664]
"CLMLServer"="c:\program files\CyberLink\Power2Go\CLMLSvc.exe" [2009-11-02 103720]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-25 136216]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-25 171032]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-25 170520]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-06-17 85160]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 947152]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 1821576]
"Iminent"="c:\program files\Iminent\Iminent.exe" [2012-06-19 1073784]
"IminentMessenger"="c:\program files\Iminent\Iminent.Messengers.exe" [2012-06-19 884856]
"ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe" [2013-01-28 1644680]
.
c:\users\Kinder\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~2\BROWSE~1\261249~1.132\{C16C1~1\BrowserProtect.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 BBSvc;BingBar Service;c:\program files\Microsoft\BingBar\7.1.391.0\BBSvc.exe [x]
R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\Common Files\MAGIX Services\Database\bin\fbserver.exe [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 NxpCap;CTX capture service;c:\windows\system32\DRIVERS\NxpCap.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUStor.sys [x]
R3 RTL8192su;%RTL8192su.DeviceDesc.DispName%;c:\windows\system32\DRIVERS\RTL8192su.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S2 BrowserProtect;BrowserProtect;c:\programdata\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe [x]
S2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files\Common Files\MAGIX Services\Database\bin\FABS.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S3 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\7.1.391.0\SeaPort.exe [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x86.sys [x]
S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys [x]
S3 WisLMSvc;WisLMSvc;c:\program files\Launch Manager\WisLMSvc.exe [x]
S3 X10Hid;X10 Hid Device;c:\windows\System32\Drivers\x10hid.sys [x]
.
.
Inhalt des "geplante Tasks" Ordners
.
2013-05-31 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-07 15:27]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mSearch Bar = hxxp://www.google.com
IE: Free YouTube Download - c:\users\Kinder\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\users\Kinder\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: {{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4
IE: {{2d930acb-2420-49dc-a746-4206b6a229dd} - {a4689b79-6a50-4cb1-b9e1-e5970c88bf96} -
TCP: DhcpNameServer = 217.0.43.145 217.0.43.129
FF - ProfilePath - c:\users\Kinder\AppData\Roaming\Mozilla\Firefox\Profiles\00xorui3.default\
FF - prefs.js: browser.search.selectedEngine - Wikipedia (de)
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
URLSearchHooks-{84FF7BD6-B47F-46F8-9130-01B2696B36CB} - (no file)
WebBrowser-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
HKCU-Run-EA Core - c:\program files\Electronic Arts\EADM\Core.exe
HKLM-Run-LMgrOSD - c:\program files\Launch Manager\OSDCtrl.exe
SafeBoot-BsScanner
AddRemove-1ClickDownload - c:\program files\SockshareDownloader.com\uninst.exe
AddRemove-Adobe Acrobat 5.0 - c:\windows\ISUN0407.EXE
AddRemove-Fire Department 3 - c:\program files\Monte Cristo\Fire Department 3\uninst.exe
AddRemove-Heroes of Might and Magic II - c:\windows\unin0407.exe
AddRemove-KAKURO Meister - c:\progra~1\KAKURO~1\UNWISE.EXE
AddRemove-Myst Masterpiece Edition - c:\windows\IsUn0407.exe
AddRemove-PricePeep - c:\program files\PricePeep\uninstall.exe
AddRemove-Rosso Rabbit in Trouble DEMO - c:\progra~1\ROSSOR~1\UNINST~1\UNWISE.EXE
AddRemove-Schatzjäger - c:\progra~1\PHENOM~1\SCHATZ~1\UNINST~1.EXE
AddRemove-SWFPlayer_is1 - c:\program files\SWFPlayer\uninst\unins000.exe
AddRemove-Totalcmd - c:\totalcmd\tcuninst.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3581923403-2550769503-572142050-1006\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:ec,20,eb,c9,cb,de,62,95,1f,b2,70,d2,2d,16,d8,60,ae,23,99,02,35,f6,5c,
b0,38,4d,4e,6d,cd,e0,ed,a9,45,f7,a3,b4,be,f2,50,8d,d9,60,12,4b,13,5c,ef,53,\
"??"=hex:41,e0,42,8c,cf,55,c7,95,2b,14,4d,f8,66,7b,0c,1b
.
[HKEY_USERS\S-1-5-21-3581923403-2550769503-572142050-1006\Software\SecuROM\License information*]
"datasecu"=hex:35,54,cb,b1,c4,a2,8a,1a,85,25,74,03,3e,0a,52,13,8c,46,b3,cb,03,
da,02,77,0a,6a,16,83,54,16,c5,e5,a5,25,a3,ee,60,7e,95,42,22,a3,20,7f,1d,0c,\
"rkeysecu"=hex:d4,05,10,c8,06,49,fc,20,e6,2e,fb,56,ef,57,f9,34
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-05-31 18:25:24
ComboFix-quarantined-files.txt 2013-05-31 16:25
.
Vor Suchlauf: 15 Verzeichnis(se), 146.294.743.040 Bytes frei
Nach Suchlauf: 21 Verzeichnis(se), 148.015.501.312 Bytes frei
.
- - End Of File - - BE340991318B0FEADF224CAE7CB13BA4 |