TheBoogeyman | 18.11.2013 20:49 | combofix Code:
ComboFix 13-11-18.01 - Thomas 18.11.2013 19:22:08.1.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3071.2053 [GMT 1:00]
ausgeführt von:: c:\users\Thomas\Desktop\ComboFix.exe
AV: G Data TotalProtection 2014 *Disabled/Updated* {545C8713-0744-B079-87F8-349A6D5C8CF0}
FW: G Data Personal Firewall *Disabled* {6C670636-4D2B-B121-ACA7-9DAF938FCB8B}
SP: G Data TotalProtection 2014 *Disabled/Updated* {EF3D66F7-217E-BFF7-BD48-0FE816DBC64D}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-10-18 bis 2013-11-18 ))))))))))))))))))))))))))))))
.
.
2013-11-18 18:37 . 2013-11-18 18:37 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-11-18 17:55 . 2013-11-18 17:58 -------- d-----w- c:\windows\system32\MRT
2013-11-15 14:12 . 2013-10-12 02:03 656896 ----a-w- c:\windows\system32\nshwfp.dll
2013-11-15 14:12 . 2013-10-12 02:01 679424 ----a-w- c:\windows\system32\IKEEXT.DLL
2013-11-15 14:12 . 2013-10-12 02:01 216576 ----a-w- c:\windows\system32\FWPUCLNT.DLL
2013-11-15 14:12 . 2013-10-03 01:58 305152 ----a-w- c:\windows\system32\gdi32.dll
2013-11-15 14:11 . 2013-10-14 06:39 7796464 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0FDAA27B-AD3F-45D6-B659-FE33B0CB85FF}\mpengine.dll
2013-11-10 16:17 . 2013-11-10 16:17 30040 ----a-w- c:\windows\system32\drivers\GRD.sys
2013-11-10 16:06 . 2013-11-10 16:06 52056 ----a-w- c:\windows\system32\drivers\PktIcpt.sys
2013-11-10 16:05 . 2013-11-10 16:05 53208 ----a-w- c:\windows\system32\drivers\gddcv32.sys
2013-11-10 16:05 . 2013-11-10 16:05 103928 ----a-w- c:\windows\system32\drivers\TS4nt.sys
2013-11-10 16:05 . 2013-11-10 16:05 70488 ----a-w- c:\windows\system32\drivers\gddcd32.sys
2013-11-10 16:05 . 2013-11-10 16:05 54104 ----a-w- c:\windows\system32\drivers\gdwfpcd32.sys
2013-11-10 16:04 . 2013-11-10 16:04 96600 ----a-w- c:\windows\system32\drivers\MiniIcpt.sys
2013-11-10 16:04 . 2013-11-10 16:04 51032 ----a-w- c:\windows\system32\drivers\HookCentre.sys
2013-11-10 16:04 . 2013-11-10 16:04 45912 ----a-w- c:\windows\system32\drivers\GDBehave.sys
2013-11-10 16:03 . 2013-11-10 16:03 -------- d-----w- c:\programdata\G DATA Software
2013-11-10 15:53 . 2013-11-10 15:53 -------- d-----w- c:\windows\system32\wbem\MOF\good
2013-11-10 15:53 . 2013-11-10 15:53 -------- d-----w- c:\windows\system32\wbem\MOF\bad
2013-11-10 15:52 . 2013-11-10 15:52 -------- d-----w- c:\windows\system32\wbem\Logs
2013-11-10 15:10 . 2013-11-18 18:08 -------- d-----w- c:\program files\Mozilla Maintenance Service
2013-11-09 15:42 . 2013-11-18 18:01 -------- d-----w- c:\windows\system32\catroot2
2013-11-09 15:35 . 2013-11-18 18:04 -------- d-----w- c:\windows\system32\wbem\repository
2013-11-09 15:27 . 2013-11-09 15:45 181064 ----a-w- c:\windows\PSEXESVC.EXE
2013-11-09 15:23 . 2013-11-09 15:23 -------- d-----w- C:\RegBackup
2013-11-04 19:27 . 2013-11-04 19:27 -------- d-----w- C:\FRST
2013-11-04 18:14 . 2013-11-09 22:25 31560 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2013-10-30 14:16 . 2013-10-30 14:17 -------- d-----w- c:\program files\CCleaner
2013-10-29 18:29 . 2013-10-30 01:28 -------- d-----w- c:\windows\ERUNT
2013-10-28 12:11 . 2013-10-28 12:11 -------- d-----w- c:\programdata\Oracle
2013-10-28 12:10 . 2013-10-28 12:10 -------- d-----w- c:\program files\Common Files\Java
2013-10-28 12:10 . 2013-10-08 06:50 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-10-27 23:25 . 2013-10-29 22:57 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2013-10-27 23:25 . 2013-10-29 23:42 -------- d-----w- c:\program files\Spybot - Search & Destroy 2
2013-10-27 22:50 . 2013-11-10 00:25 -------- d-----w- C:\#GDATA.Trash.Store#
2013-10-27 21:08 . 2013-11-09 13:01 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2013-10-27 14:15 . 2013-11-18 17:45 -------- d-----w- C:\AdwCleaner
2013-10-23 21:21 . 2013-10-23 21:21 -------- d-----w- c:\users\Thomas\AppData\Roaming\G Data
2013-10-23 19:35 . 2013-11-10 16:17 16048 ----a-w- c:\windows\system32\drivers\GdPhyMem.sys
2013-10-23 16:20 . 2012-05-04 09:59 514560 ----a-w- c:\windows\system32\qdvd.dll
2013-10-20 18:15 . 2013-09-04 01:15 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys
2013-10-20 18:15 . 2013-09-04 01:14 284672 ----a-w- c:\windows\system32\drivers\usbport.sys
2013-10-20 18:15 . 2013-09-04 01:14 43008 ----a-w- c:\windows\system32\drivers\usbehci.sys
2013-10-20 18:15 . 2013-09-04 01:14 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2013-10-20 18:15 . 2013-09-04 01:14 6016 ----a-w- c:\windows\system32\drivers\usbd.sys
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-10-28 12:18 . 2012-10-13 20:00 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-10-28 12:18 . 2011-06-03 09:28 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-09-14 00:48 . 2013-10-10 18:20 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2013-09-08 02:07 . 2013-10-10 18:20 1294272 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-09-08 02:03 . 2013-10-10 18:20 231424 ----a-w- c:\windows\system32\mswsock.dll
2013-09-03 12:35 . 2010-06-29 13:41 238872 ------w- c:\windows\system32\MpSigStub.exe
2013-09-01 13:38 . 2013-09-01 13:38 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2013-09-01 13:24 . 2013-09-01 13:24 2406 ----a-w- c:\windows\system32\ealregsnapshot1.reg
2013-08-29 01:51 . 2013-10-10 18:20 3969472 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-08-29 01:51 . 2013-10-10 18:20 3914176 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-08-29 01:50 . 2013-10-10 18:20 1289096 ----a-w- c:\windows\system32\ntdll.dll
2013-08-29 01:50 . 2013-10-10 18:20 619520 ----a-w- c:\windows\system32\tdh.dll
2013-08-29 01:48 . 2013-10-10 18:20 640512 ----a-w- c:\windows\system32\advapi32.dll
2013-08-28 01:04 . 2013-10-10 18:18 2348544 ----a-w- c:\windows\system32\win32k.sys
2013-08-28 00:57 . 2013-10-10 18:20 434688 ----a-w- c:\windows\system32\scavengeui.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Akamai NetSession Interface"="c:\users\Thomas\AppData\Local\Akamai\netsession_win.exe" [2013-06-04 4489472]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-03-04 284696]
"CLMLServer"="c:\program files\CyberLink\Power2Go\CLMLSvc.exe" [2009-11-02 103720]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-04-07 8555040]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-05-27 98304]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"AGEIA PhysX SysTray"="c:\program files\AGEIA Technologies\TrayIcon.exe" [2006-03-20 331776]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2010-06-09 49208]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-05-11 958576]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"G Data AntiVirus Tray"="c:\program files\G Data\TotalProtection\AVKTray\AVKTray.exe" [2013-08-21 1444472]
"GDFirewallTray"="c:\program files\G Data\TotalProtection\Firewall\GDFirewallTray.exe" [2013-03-22 1854928]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableSecureUIAPath"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2013-04-21 19:43 59720 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core]
2009-03-28 21:11 3325952 ----a-w- c:\program files\Electronic Arts\EADM\Core.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
2008-07-22 17:33 150528 ----a-w- c:\program files\HP\Digital Imaging\bin\HpqSRmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2013-05-31 09:56 152392 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDFPrint]
2012-12-12 09:28 163000 ----a-w- c:\program files\PDF24\pdf24.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2013-05-01 01:59 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony PC Companion]
2013-05-29 11:34 449248 ----a-w- c:\program files\Sony\Sony PC Companion\PCCompanion.exe
.
R1 A2DDA;A2 Direct Disk Access Support Driver;c:\users\THOMAS\DOWNLOADS\EMSISOFTEMERGENCYKIT\RUN\a2ddax86.sys [x]
R2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-04-04 418376]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-06-03 162408]
R3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2011-05-26 191752]
R3 cleanhlp;cleanhlp;c:\users\Thomas\Downloads\EmsisoftEmergencyKit\Run\cleanhlp32.sys [x]
R3 GdNetMon;G Data Network Monitor;c:\windows\system32\drivers\GdNetMon32.sys [2011-05-14 29400]
R3 GDTunerSvc;G Data Tuner Service;c:\program files\G Data\TotalProtection\AVKTuner\AVKTunerService.exe [2013-02-25 1711568]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2013-11-18 108032]
R3 mbamchameleon;mbamchameleon;c:\windows\system32\drivers\mbamchameleon.sys [2013-11-09 31560]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-04-04 22856]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 Sony PC Companion;Sony PC Companion;c:\program files\Sony\Sony PC Companion\PCCService.exe [2013-02-04 155824]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 49664]
S0 GDBehave;GDBehave;c:\windows\system32\drivers\GDBehave.sys [2013-11-10 45912]
S0 TS4NT;TS4nt driver;c:\windows\System32\Drivers\TS4nt.sys [2013-11-10 103928]
S1 gddcv;G Data DCV Driver;c:\windows\system32\drivers\gddcv32.sys [2013-11-10 53208]
S1 GDMnIcpt;GDMnIcpt;c:\windows\system32\drivers\MiniIcpt.sys [2013-11-10 96600]
S1 gdwfpcd;G Data WFP CD;c:\windows\system32\drivers\gdwfpcd32.sys [2013-11-10 54104]
S1 GRD;G Data Rootkit Detector Driver;c:\windows\system32\drivers\GRD.sys [2013-11-10 30040]
S1 HookCentre;HookCentre;c:\windows\system32\drivers\HookCentre.sys [2013-11-10 51032]
S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [2010-02-24 185472]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 20992]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-05-27 176128]
S2 AVKProxy;G Data AntiVirus Proxy;c:\program files\Common Files\G Data\AVKProxy\AVKProxy.exe [2013-08-26 1970296]
S2 AVKService;G Data Scheduler;c:\program files\G Data\TotalProtection\AVK\AVKService.exe [2013-08-21 635000]
S2 AVKWCtl;G Data Dateisystem Wächter;c:\program files\G Data\TotalProtection\AVK\AVKWCtl.exe [2013-10-15 2101280]
S2 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\SeaPort.EXE [2011-03-10 249648]
S2 cvhsvc;Client Virtualization Handler;c:\program files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2013-04-22 822504]
S2 GDBackupSvc;G Data Backup Service;c:\program files\G Data\TotalProtection\AVKBackup\AVKBackupService.exe [2013-08-21 1947768]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-03-04 13336]
S2 sftlist;Application Virtualization Client;c:\program files\Microsoft Application Virtualization Client\sftlist.exe [2013-06-26 523944]
S3 gddcd;G Data DCD Driver;c:\windows\system32\drivers\gddcd32.sys [2013-11-10 70488]
S3 GDFwSvc;G Data Personal Firewall;c:\program files\G Data\TotalProtection\Firewall\GDFwSvc.exe [2013-10-17 2373712]
S3 GDPkIcpt;GDPkIcpt;c:\windows\system32\drivers\PktIcpt.sys [2013-11-10 52056]
S3 GDScan;G Data Scanner;c:\program files\Common Files\G Data\GDScan\GDScan.exe [2013-08-22 695416]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2011-06-10 394856]
S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys [2010-11-25 603240]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2013-06-26 583848]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2013-06-26 197800]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2013-06-26 24232]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2013-06-26 20136]
S3 sftvsa;Application Virtualization Service Agent;c:\program files\Microsoft Application Virtualization Client\sftvsa.exe [2013-06-26 207528]
S3 TSNxGService;G Data Datensafe Service;c:\program files\G Data\TotalProtection\TSNxG\TSNxGService.exe [2013-02-25 257512]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
Akamai REG_MULTI_SZ Akamai
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
Inhalt des "geplante Tasks" Ordners
.
2013-11-18 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-13 12:18]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.aldi.com
uInternet Settings,ProxyOverride = <local>
IE: An OneNote s&enden - c:\progra~1\MICROS~3\Office14\ONBttnIE.dll/105
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000
TCP: Interfaces\{3C7E6CD9-BDFA-4788-AA0F-146DE9693532}: NameServer = 192.168.2.1
FF - ProfilePath - c:\users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\i9o97yj6.default\
FF - ExtSQL: !HIDDEN! 2010-12-25 21:49; smartwebprinting@hp.com; c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
SafeBoot-CleanHlp
SafeBoot-CleanHlp.sys
SafeBoot-BsScanner
AddRemove-DigitalSite - c:\users\Thomas\AppData\Roaming\DIGITA~1\UpdateProc\UpdateTask.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Akamai]
"ServiceDll"="c:\program files\common files\akamai/netsession_win_8fa3539.dll"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-600205669-1944798074-3299241248-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:ee,4e,a2,ee,bb,70,1c,88,fa,3a,e6,b2,9f,9b,8f,26,ca,b8,ea,74,70,b1,58,
bb,69,3a,ab,41,5c,1c,ad,2c,c9,43,f4,62,b9,c3,49,80,01,9a,0e,67,23,09,ef,b6,\
"??"=hex:39,4b,f5,c4,a1,1d,a1,99,d8,91,35,4f,a5,a7,bf,8b
.
[HKEY_USERS\S-1-5-21-600205669-1944798074-3299241248-1000\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
"datasecu"=hex:e1,15,9f,7b,b9,9b,5b,5e,9b,8c,eb,1a,fc,4d,95,ba,b1,d0,e4,6c,b7,
61,18,a5,14,4e,eb,6d,92,c9,b5,44,3b,83,c9,12,3b,69,09,26,46,66,5e,71,1b,ba,\
"rkeysecu"=hex:d3,21,26,3b,bd,60,ad,18,15,cf,3a,23,1f,74,49,36
.
Zeit der Fertigstellung: 2013-11-18 20:41:08
ComboFix-quarantined-files.txt 2013-11-18 19:41
.
Vor Suchlauf: 19 Verzeichnis(se), 807.684.739.072 Bytes frei
Nach Suchlauf: 20 Verzeichnis(se), 807.635.042.304 Bytes frei
.
- - End Of File - - C95D2E9C5651BCADF193E2E23216A885
C79B30CB8852157F6F908E4698CFE0D0 |