walter_h | 11.12.2013 23:33 | Code:
ComboFix 13-12-10.01 - Neum 11.12.2013 21:58:03.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.49.1031.18.2047.1298 [GMT 1:00]
ausgeführt von:: c:\dokumente und einstellungen\Neum\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\dokume~1\Neum\LOKALE~1\Temp\1.tmp\F_IN_BOX.dll
c:\dokumente und einstellungen\Neum\Lokale Einstellungen\Temp\1.tmp\F_IN_BOX.dll
c:\windows\system32\drivers\etc\lmhosts
c:\windows\system32\setup.ini
c:\windows\system32\win.ini
c:\windows\wininit.ini
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-11-11 bis 2013-12-11 ))))))))))))))))))))))))))))))
.
.
2013-12-11 21:28 . 2013-12-11 21:28 9272200 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2013-12-11 19:38 . 2013-12-11 19:38 -------- d-----w- C:\FRST
2013-12-08 12:03 . 2013-12-08 12:03 -------- d-----w- c:\dokumente und einstellungen\Neum\Anwendungsdaten\HarmonicTune
2013-11-25 17:46 . 2013-11-28 18:33 -------- d-----w- c:\dokumente und einstellungen\Neum\Anwendungsdaten\klickTel
2013-11-17 13:42 . 2013-11-17 13:42 -------- d-----w- c:\dokumente und einstellungen\Neum\Anwendungsdaten\vlc
2013-11-15 21:30 . 2013-11-15 21:33 -------- d-----w- c:\dokumente und einstellungen\Neum\Lokale Einstellungen\Anwendungsdaten\Google
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-12-11 21:29 . 2012-04-11 12:36 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-12-11 21:29 . 2011-05-19 16:22 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-12-05 22:01 . 2013-09-04 12:05 90400 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-11-25 20:56 . 2009-05-21 18:18 1080 ----a-w- c:\windows\AUTOLNCH.REG
2013-11-19 14:29 . 2013-09-04 12:05 37352 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2013-11-19 14:29 . 2013-09-04 12:05 137208 ----a-w- c:\windows\system32\drivers\avipbb.sys
2013-10-13 07:22 . 1979-12-31 22:00 920064 ----a-w- c:\windows\system32\wininet.dll
2013-10-13 07:22 . 1979-12-31 22:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2013-10-13 07:22 . 1979-12-31 22:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2013-10-13 07:21 . 1979-12-31 22:00 18944 ----a-w- c:\windows\system32\corpol.dll
2013-10-13 06:57 . 2009-05-21 15:33 385024 ----a-w- c:\windows\system32\html.iec
2013-10-12 15:56 . 1979-12-31 22:00 279552 ----a-w- c:\windows\system32\oakley.dll
2013-10-09 13:12 . 1979-12-31 22:00 287744 ----a-w- c:\windows\system32\gdi32.dll
2013-10-08 05:50 . 2013-10-17 16:43 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-10-08 05:29 . 2013-10-17 16:44 145408 ----a-w- c:\windows\system32\javacpl.cpl
2013-10-07 10:59 . 1979-12-31 22:00 608256 ----a-w- c:\windows\system32\crypt32.dll
2013-10-05 01:42 . 2008-05-05 05:25 8192 ----a-w- c:\windows\system32\xpsp4res.dll
2009-06-18 11:16 . 2013-11-16 08:54 10437264 ----a-w- c:\programme\mozilla firefox\plugins\PDFNetC.dll
2009-06-18 11:36 . 2013-11-16 08:54 108272 ----a-w- c:\programme\mozilla firefox\plugins\ScorchPDFWrapper.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7}]
2013-10-23 19:52 12240 ----a-w- c:\programme\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{41564952-412D-5637-00A7-7A786E7484D7}"= "c:\programme\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll" [2013-10-23 12240]
.
[HKEY_CLASSES_ROOT\clsid\{41564952-412d-5637-00a7-7a786e7484d7}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ibmmessages"="c:\programme\IBM\Messages By IBM\ibmmessages.exe" [2002-12-19 491520]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"S3TRAY2"="S3Tray2.exe" [2002-07-15 69632]
"SynTPLpr"="c:\programme\Synaptics\SynTP\SynTPLpr.exe" [2008-07-03 118784]
"SynTPEnh"="c:\programme\Synaptics\SynTP\SynTPEnh.exe" [2008-07-03 1323008]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 28672]
"BluetoothAuthenticationAgent"="irprops.cpl" [2008-04-14 380928]
"QCWLICON"="c:\programme\ThinkPad\ConnectUtilities\QCWLICON.EXE" [2003-03-27 53248]
"TPHOTKEY"="c:\progra~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe" [2006-10-02 94208]
"BMMGAG"="c:\progra~1\ThinkPad\UTILIT~1\pwrmonit.dll" [2002-10-31 64000]
"TPKMAPMN"="c:\programme\ThinkPad\Utilities\TpKmapMn.exe" [2003-02-16 32835]
"TP4EX"="tp4ex.exe" [2002-09-03 53248]
"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2002-11-01 204800]
"tgcmd"="c:\programme\Support.com\bin\tgcmd.exe" [2002-10-16 1622016]
"ibmmessages"="c:\programme\IBM\Messages By IBM\ibmmessages.exe" [2002-12-19 491520]
"StorageGuard"="c:\programme\VERITAS Software\Update Manager\sgtray.exe" [2002-06-17 155648]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2002-11-08 106551]
"HP Lamp"="c:\programme\Hewlett-Packard\HP PrecisionScan\PrecisionScan Pro\hplamp.exe" [2001-04-27 53248]
"FreePDF Assistant"="c:\programme\FreePDF_XP\fpassist.exe" [2008-07-22 357376]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"NPDTRAY"="c:\progra~1\ThinkPad\UTILIT~1\NPDTray.exe" [2002-10-30 204800]
"ArcSoft Connection Service"="c:\programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-27 207424]
"OODefragTray"="c:\windows\system32\oodtray.exe" [2008-09-30 2528512]
"AGRSMMSG"="AGRSMMSG.exe" [2002-10-18 87751]
"M-Audio Taskbar Icon"="c:\windows\system32\MAFWTray.exe" [2009-07-29 252424]
"InstaLAN"="c:\programme\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe" [2011-05-27 2015136]
"Adobe ARM"="c:\programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"LexwareInfoService"="c:\programme\Gemeinsame Dateien\Lexware\Update Manager\LxUpdateManager.exe" [2011-07-31 189808]
"avgnt"="c:\programme\Avira\AntiVir Desktop\avgnt.exe" [2013-11-19 683576]
"ApnTBMon"="c:\programme\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe" [2013-10-23 1673680]
"SunJavaUpdateSched"="c:\programme\Gemeinsame Dateien\Java\Java Update\jusched.exe" [2013-07-02 254336]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\
Microsoft Office.lnk - c:\programme\Microsoft Office\Office\OSA9.EXE -b -l [2000-1-21 65588]
NDAS Geräte-Manager.lnk - c:\programme\NDAS\System\ndasmgmt.exe /startup [2010-1-13 283112]
TMMonitor.lnk - c:\programme\ArcSoft\TotalMedia 3.5\TMMonitor.exe [2010-5-22 258048]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2005-07-05 22:45 28672 ----a-w- c:\windows\system32\notifyf2.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2005-11-30 19:16 24576 ----a-w- c:\windows\system32\tphklock.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /r \??\f:\0autocheck autochk *\0OODBS
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\IBMTOOLS\\Updater\\jre\\bin\\javaw.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Programme\\Support.com\\Bin\\tgcmd.exe"=
"c:\\Programme\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Programme\\SiSoftware\\SiSoftware Sandra Lite 2011.SP1\\RpcAgentSrv.exe"=
"c:\\Programme\\SiSoftware\\SiSoftware Sandra Lite 2011.SP1\\WNt500x86\\RpcSandraSrv.exe"=
"c:\\Programme\\NetGear\\ProSafe Plus Utility\\ProSafe Plus Utility.exe"=
"c:\\Programme\\NetGear\\ProSafe Plus Utility\\NetGearServer.exe"=
"c:\\Programme\\NetGear\\ProSafe Plus Utility\\NsdpManager.exe"=
"c:\\Programme\\Belkin\\Belkin USB Print and Storage Center\\Connect.exe"=
"c:\\Programme\\Sybase\\SQL Anywhere 9\\win32\\dbsrv9.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"19540:UDP"= 19540:UDP:SXUPTP
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
.
R0 fltsrv;Acronis Storage Filter Management;c:\windows\system32\drivers\fltsrv.sys [11.04.2012 14:08 77696]
R0 ndasfs;ndasfs;c:\windows\system32\drivers\ndasfs.sys [13.01.2010 09:12 562152]
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [04.09.2013 13:05 37352]
R1 HWiNFO32;HWiNFO32 Kernel Driver;c:\programme\HWiNFO32\HWiNFO32.SYS [06.03.2011 01:00 20088]
R1 ndasfat;NDAS FAT File System Service;c:\windows\system32\drivers\ndasfat.sys [13.01.2010 09:12 461288]
R1 ndasrofs;NDAS ROFS File System Service;c:\windows\system32\drivers\ndasrofs.sys [13.01.2010 09:12 791528]
R2 drhard;drhard;c:\windows\system32\drivers\drhard.sys [06.03.2011 02:24 23600]
R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [25.06.2010 18:07 35088]
R3 AVMWAN;NDIS WAN CAPI Treiber;c:\windows\system32\drivers\avmwan.sys [16.07.2002 01:00 37568]
R3 FXUSBASE;Teledat X120 (WinXP/2000);c:\windows\system32\drivers\fxusbase.sys [16.07.2002 01:00 498672]
R3 hpusbfd;Hewlett-Packard USB Filter Class;c:\windows\system32\drivers\hpusbfd.sys [25.05.2009 15:46 7552]
S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\drivers\dc3d.sys [09.05.2012 16:29 45288]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\programme\Lavasoft\Ad-Aware\KernExplorer.sys --> c:\programme\Lavasoft\Ad-Aware\KernExplorer.sys [?]
S3 LucentSoftModem;Lucent Technologies Soft Modem;c:\windows\system32\drivers\LTSM.sys [01.10.2002 08:44 802683]
S3 MAFW;Service for M-Audio FireWire;c:\windows\system32\drivers\mafw.sys [12.12.2010 21:28 192392]
S3 NETPPPOI;PPP over ISDN;c:\windows\system32\drivers\NETPPPOI.SYS [23.05.2009 23:53 259072]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys --> c:\windows\system32\drivers\nmwcdnsu.sys [?]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys --> c:\windows\system32\drivers\nmwcdnsuc.sys [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-12-06 02:42 1210320 ----a-w- c:\programme\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2013-12-11 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-11 21:29]
.
2013-12-05 c:\windows\Tasks\BMMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\BMMTASK.EXE [2009-05-21 23:31]
.
2013-12-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programme\Google\Update\GoogleUpdate.exe [2013-11-15 21:29]
.
2013-12-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programme\Google\Update\GoogleUpdate.exe [2013-11-15 21:29]
.
2013-12-11 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-3264421748-380149622-3910952666-1004.job
- c:\progra~1\Real\______~1\realupgrade.exe [2010-11-05 10:33]
.
2013-12-10 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-3264421748-380149622-3910952666-1004.job
- c:\progra~1\Real\______~1\realupgrade.exe [2010-11-05 10:33]
.
.
------- Zusätzlicher Suchlauf -------
.
IE: Bild in &Microsoft PhotoDraw öffnen - c:\progra~1\MICROS~3\Office\1031\phdintl.dll/phdContext.htm
LSP: c:\programme\Avira\AntiVir Desktop\avsda.dll
TCP: Interfaces\{A29C7FE0-06D5-4939-85EE-10AC7B3EB02A}: NameServer = 192.168.121.252,192.168.121.253
TCP: Interfaces\{B54CB423-672B-427E-8E56-2233D6FB9A46}: NameServer = 192.168.1.2
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\dokumente und einstellungen\Neum\Anwendungsdaten\Mozilla\Firefox\Profiles\it7ytsqx.default\
FF - prefs.js: browser.startup.homepage - www.gmx.de
FF - ExtSQL: 2013-10-31 21:38; {73a6fe31-595d-460b-a920-fcc0f8843232}; c:\dokumente und einstellungen\Neum\Anwendungsdaten\Mozilla\Firefox\Profiles\it7ytsqx.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
FF - ExtSQL: 2013-10-31 21:38; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\dokumente und einstellungen\Neum\Anwendungsdaten\Mozilla\Firefox\Profiles\it7ytsqx.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
SafeBoot-Wdf01000.sys
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2013-12-11 22:28
Windows 5.1.2600 Service Pack 3 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
tgcmd = "c:\programme\Support.com\bin\tgcmd.exe" /server?ver
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,c1,43,65,99,a6,ce,a6,48,99,41,4e,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,c1,43,65,99,a6,ce,a6,48,99,41,4e,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG08.00.00.01WORKSTATION"="6152A02BDDF17CE9998BC00FD8333D54B68A015F02258B4480D62E7111E2C80269C5C4628504EFD079BC9C8835EAAC37048B6705AE23C04FB34DF85BE650B1A66365E41ABC2C573740FE719AC51427E14CA94845F4AAE0851B7E107184827BA376D3BB4C3A61ED8EBE0443D57606C3ABA3CA96E7959301CA309FF1562074D40324B7F2144BDD21AA95860BEEC85E4C54F15538DBE87C69E33FE813D107632535BA3CAB31D1A294443CBF363FD2FC42FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933C038D530D6EB3452A2D97226D213B555A6171C11EC38DE3D6A9A726AA28811D492A04A1C8EBB38B7166762CBD798AC2246B93B5F92A1AB110E1D72786430BB31A53A87A68486006B5819AF613D2B144ED3A6C0518F9EFC410C0E24F3D6D924072CE1E082099F69169C14AE31FA193DBA903E1CB8BF4E558BAC38CA3513DC642FB786ADD44E92ED6E5C0DE4CDFAC4229AFE18A63367064DC39B392C8753265539BA6AC2342902C8DF758ADB3E4CA37FD785A2B5D3EBB2C36FE703922CF7B597670FA4FB3012237B0AA8E89E7B1EBF568CED9E2A23D8D1DBC5835ACD55069E0DB0701FBA49A63EC9411D58BEF2C838EC8C68A0639A5D78F9B648DA2F2CA30CDDBEFE9AE1F2A7323B0C59DCCF88C5404B59051149A9CACCC86270708ECD9D3774F0BEA7D718F76E1C274C4DEB11B11CBD2DBA2D44B21A0BB79F9B5E46C7E4F001581A2E0A94A3797C00C755AE5650265773E584C08EE48177F64B39B49F8C9FF43EDBE7E6BAD5EC313C00753997854EEC4D42FCB207EA94FE266AEABC4E4BBA091A3465634EDFF451331001B0855D951710734F0FDB0EBA071E4233C43D7ECCB89CB8087508B6D23A6E73A03CC68493B24301884EBFD57E90850321B7CEA577C1A7E0079A1672DD8BAF8D4F8975CCF06223D308EFD86D805A353F9B83D5E4EE28D089EC5019D07C296AA15C4A9FACEB89A13A05F34223736DBB6EDC1C9B047B326473991C26B2ADBAC3DA6C30C63C5851E06706E00DE91F92596C71F75A6DF8EB5FC13F05C69D81AE1AC5F677603D1C28BC7168413AD95E5783F83D114334D824F57DE296F5389FB1FA54485AD80EB03F3E53DDA0C12C200FE3B673E579899DED0C14E1E02851BEBB2B5B7F990CB5A40AA86A69918D40E8CF59AC9F79164661A0BE5469763F5A2E02229410FACD5E1AC3EE79E5AAFD1A4EF2F3489FD2A4E54F575CF37DEF16E54D810A9D43C6615548E73BA67E0466DEFC18F957A47B260927F1E40AF3E978AF91FAC3F63349038DF738E77D35BC0B5BB31FE48CB3830CF3BE1291947702A79186F26286D052619C883B07EADDF42A7DC4306081287DC08C7DA0CCF208DC590FC7AFAD165EB99B3BECB7DB432254F0D69834D1AF"
"OODEFRAG10.00.00.01WORKSTATION"="7EC9439BEDA7EA89F0AFA73825271254445633E989A5B7FD762E4EDA768AC571CF617BF160FB320A07575C57488D00097F04B448BDB5594A130A94BBF19535556BA9FE585C148BB86D012DB7E6459FB5B59ED9FA37A1D4BF1DDF2130FB8D93C35AA1EE8554B7C3C729C1FE4E3F3BCEDB027066569C1A38CBEA4D388A4308C435CD5BB1E8A1FE3061E0C076C571ABF2EEA75562E1F6A21A51F705E3CFD8ECAC1C9680F123FDD725A0613B81FC812B72D80ABF19D9341511A55FCDF037347836D8AB4A1D0B0905FE9499014C86D620B97631B59C2B261ABC13E581702DB03C4FC3A909E429469B9B439E76CC2ABFC437994C4DBFFB80B43B58FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808A2D97226D213B555BA7FD869164D6794A6171C11EC38DE3DD88A0474420B15142B18AC557C61AF6A39C608339B4AE162B4FEE19922C29A6926B7A44B43CB9C8422CC6893E3D713879C9790ECAF1E3D2739E5787239AB1D513E3736282F4E45DA89CFE58E9A4E2A009D150704B5730DA8BA41ED7D4B64EE0E8E64C309AC4517A0E3320F21AF3AACC5F8255753C4A65CE8D1EB50B2984E89D0262E1C21C4B89DD0DB1995DA9468574691C1B3E4D7E7B6DF365670BA4221EB3D391AD1D4E181E85FBEBEEC009D786BDDEC7A107ACBBC2E764A02E4F2D1E41A6C9F40BB4155CF0B30FA6F4E06055F2D5E3571278864FCD90E0E0789EB30F799E8554DF53454261E1BA78C351CE7E2E30F385C743847D5D2792991F96CAF8BF334FA01DF2E76D9BB6EFD8BE09DC7205E296885BAE37EC9B57D68DF9AEC01A63A4052AE9B68379885EB597656210A076C5B5ACAFD1F792AA5573946901C3EA1FC7745BF914C785E9C46BA68DDEC78DA62C5C91F08AB0B22C7B52DA9C45CE0AB54B4DFB16BF87E7FAAA8C894837C3F33998092096604E7AE45BBFD876740C8C5DA47CF91194071A2DA30CA40978070FCEE953822E8D3AA1F4B7F05EE6993B9C5ADF4EB07CD285DC25C6B2EC32EDA82F5C1015F9826FAD3190D8C418282D2DA5671F42AC801EC33AC63E1048D9FA34DB3F637533075104395BF6255792A3137F24B7226A26D7AC686280B801D07278F1DF79C01BC7659C0E01C728820A1113E6FE68EA1F412F65044E4D5FC0AC464E8EDB18CFAAA8754F69BE0A6C554681044F0F25CFE35B2B56DB1D820767B7E8E603793D37577503272BBCED69B8AC6F77FF1A0E5C66BD5C21DEDC9428D309B0E5FDA93B44C35395528882C543DC945CC0C3FA725A432C65CC46A7E04877847FCB291A866FC0A6ED9EC9FC2E0032D32C2E97AC20A683C94742DEFC1224EB9F22C8B67519029B062887B71DF34E4E2A043FA1AB07986CB1333819764CD6C6E511E7F3C8D539777C864F1C254F8"
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'winlogon.exe'(928)
c:\windows\system32\tphklock.dll
.
- - - - - - - > 'lsass.exe'(984)
c:\programme\Avira\AntiVir Desktop\avsda.dll
.
- - - - - - - > 'explorer.exe'(2328)
c:\windows\system32\msi.dll
c:\progra~1\ThinkPad\UTILIT~1\pwrmonit.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\programme\Avira\AntiVir Desktop\sched.exe
c:\programme\Belkin\Router Setup and Monitor\BelkinService.exe
c:\programme\Avira\AntiVir Desktop\avguard.exe
c:\programme\AskPartnerNetwork\Toolbar\apnmcp.exe
c:\windows\System32\Ati2evxx.exe
c:\programme\Belkin\Belkin USB Print and Storage Center\BkBackupScheduler.exe
c:\programme\Belkin\Belkin USB Print and Storage Center\Bkapcs.exe
c:\programme\Java\jre7\bin\jqs.exe
c:\programme\Sybase\SQL Anywhere 9\win32\dbsrv9.exe
c:\programme\NDAS\System\ndassvc.exe
c:\windows\system32\netdde.exe
c:\programme\CDBurnerXP\NMSAccessU.exe
c:\windows\system32\oodag.exe
c:\programme\TP-LINK\TP-LINK Wireless Configuration Utility\Service\RaRegistry.exe
c:\windows\System32\RegSrvc.exe
c:\programme\TomTom HOME 2\TomTomHOMEService.exe
c:\programme\Avira\AntiVir Desktop\avshadow.exe
c:\programme\Avira\AntiVir Desktop\AVWEBGRD.EXE
c:\windows\System32\wbem\wmiapsrv.exe
c:\windows\system32\RunDll32.exe
c:\programme\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
c:\programme\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
c:\windows\AGRSMMSG.exe
c:\programme\Belkin\Belkin USB Print and Storage Center\connect.exe
c:\programme\NDAS\System\ndasmgmt.exe
c:\programme\Belkin\Router Setup and Monitor\BelkinSetup.exe
c:\programme\Belkin\Router Setup and Monitor\dlnaPlugin.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2013-12-11 22:48:44 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2013-12-11 21:48
.
Vor Suchlauf: 27 Verzeichnis(se), 31.889.244.160 Bytes frei
Nach Suchlauf: 28 Verzeichnis(se), 31.847.841.792 Bytes frei
.
- - End Of File - - 287831FDECEA2EC4A982B7713873B467
AB67D479E4EE1CCAD757294B60DDB98F Das ist die combofix-Datei. Es gab auch noch eine log-datei: Code:
ComboFix 13-12-10.01 - Neum 11.12.2013 21:58:03.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.49.1031.18.2047.1298 [GMT 1:00]
ausgeführt von:: c:\dokumente und einstellungen\Neum\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\dokume~1\Neum\LOKALE~1\Temp\1.tmp\F_IN_BOX.dll
c:\dokumente und einstellungen\Neum\Lokale Einstellungen\Temp\1.tmp\F_IN_BOX.dll
c:\windows\system32\drivers\etc\lmhosts
c:\windows\system32\setup.ini
c:\windows\system32\win.ini
c:\windows\wininit.ini
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-11-11 bis 2013-12-11 ))))))))))))))))))))))))))))))
.
.
2013-12-11 21:28 . 2013-12-11 21:28 9272200 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2013-12-11 19:38 . 2013-12-11 19:38 -------- d-----w- C:\FRST
2013-12-08 12:03 . 2013-12-08 12:03 -------- d-----w- c:\dokumente und einstellungen\Neum\Anwendungsdaten\HarmonicTune
2013-11-25 17:46 . 2013-11-28 18:33 -------- d-----w- c:\dokumente und einstellungen\Neum\Anwendungsdaten\klickTel
2013-11-17 13:42 . 2013-11-17 13:42 -------- d-----w- c:\dokumente und einstellungen\Neum\Anwendungsdaten\vlc
2013-11-15 21:30 . 2013-11-15 21:33 -------- d-----w- c:\dokumente und einstellungen\Neum\Lokale Einstellungen\Anwendungsdaten\Google
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-12-11 21:29 . 2012-04-11 12:36 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-12-11 21:29 . 2011-05-19 16:22 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-12-05 22:01 . 2013-09-04 12:05 90400 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-11-25 20:56 . 2009-05-21 18:18 1080 ----a-w- c:\windows\AUTOLNCH.REG
2013-11-19 14:29 . 2013-09-04 12:05 37352 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2013-11-19 14:29 . 2013-09-04 12:05 137208 ----a-w- c:\windows\system32\drivers\avipbb.sys
2013-10-13 07:22 . 1979-12-31 22:00 920064 ----a-w- c:\windows\system32\wininet.dll
2013-10-13 07:22 . 1979-12-31 22:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2013-10-13 07:22 . 1979-12-31 22:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2013-10-13 07:21 . 1979-12-31 22:00 18944 ----a-w- c:\windows\system32\corpol.dll
2013-10-13 06:57 . 2009-05-21 15:33 385024 ----a-w- c:\windows\system32\html.iec
2013-10-12 15:56 . 1979-12-31 22:00 279552 ----a-w- c:\windows\system32\oakley.dll
2013-10-09 13:12 . 1979-12-31 22:00 287744 ----a-w- c:\windows\system32\gdi32.dll
2013-10-08 05:50 . 2013-10-17 16:43 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-10-08 05:29 . 2013-10-17 16:44 145408 ----a-w- c:\windows\system32\javacpl.cpl
2013-10-07 10:59 . 1979-12-31 22:00 608256 ----a-w- c:\windows\system32\crypt32.dll
2013-10-05 01:42 . 2008-05-05 05:25 8192 ----a-w- c:\windows\system32\xpsp4res.dll
2009-06-18 11:16 . 2013-11-16 08:54 10437264 ----a-w- c:\programme\mozilla firefox\plugins\PDFNetC.dll
2009-06-18 11:36 . 2013-11-16 08:54 108272 ----a-w- c:\programme\mozilla firefox\plugins\ScorchPDFWrapper.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7}]
2013-10-23 19:52 12240 ----a-w- c:\programme\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{41564952-412D-5637-00A7-7A786E7484D7}"= "c:\programme\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll" [2013-10-23 12240]
.
[HKEY_CLASSES_ROOT\clsid\{41564952-412d-5637-00a7-7a786e7484d7}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ibmmessages"="c:\programme\IBM\Messages By IBM\ibmmessages.exe" [2002-12-19 491520]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"S3TRAY2"="S3Tray2.exe" [2002-07-15 69632]
"SynTPLpr"="c:\programme\Synaptics\SynTP\SynTPLpr.exe" [2008-07-03 118784]
"SynTPEnh"="c:\programme\Synaptics\SynTP\SynTPEnh.exe" [2008-07-03 1323008]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 28672]
"BluetoothAuthenticationAgent"="irprops.cpl" [2008-04-14 380928]
"QCWLICON"="c:\programme\ThinkPad\ConnectUtilities\QCWLICON.EXE" [2003-03-27 53248]
"TPHOTKEY"="c:\progra~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe" [2006-10-02 94208]
"BMMGAG"="c:\progra~1\ThinkPad\UTILIT~1\pwrmonit.dll" [2002-10-31 64000]
"TPKMAPMN"="c:\programme\ThinkPad\Utilities\TpKmapMn.exe" [2003-02-16 32835]
"TP4EX"="tp4ex.exe" [2002-09-03 53248]
"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2002-11-01 204800]
"tgcmd"="c:\programme\Support.com\bin\tgcmd.exe" [2002-10-16 1622016]
"ibmmessages"="c:\programme\IBM\Messages By IBM\ibmmessages.exe" [2002-12-19 491520]
"StorageGuard"="c:\programme\VERITAS Software\Update Manager\sgtray.exe" [2002-06-17 155648]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2002-11-08 106551]
"HP Lamp"="c:\programme\Hewlett-Packard\HP PrecisionScan\PrecisionScan Pro\hplamp.exe" [2001-04-27 53248]
"FreePDF Assistant"="c:\programme\FreePDF_XP\fpassist.exe" [2008-07-22 357376]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"NPDTRAY"="c:\progra~1\ThinkPad\UTILIT~1\NPDTray.exe" [2002-10-30 204800]
"ArcSoft Connection Service"="c:\programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-27 207424]
"OODefragTray"="c:\windows\system32\oodtray.exe" [2008-09-30 2528512]
"AGRSMMSG"="AGRSMMSG.exe" [2002-10-18 87751]
"M-Audio Taskbar Icon"="c:\windows\system32\MAFWTray.exe" [2009-07-29 252424]
"InstaLAN"="c:\programme\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe" [2011-05-27 2015136]
"Adobe ARM"="c:\programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"LexwareInfoService"="c:\programme\Gemeinsame Dateien\Lexware\Update Manager\LxUpdateManager.exe" [2011-07-31 189808]
"avgnt"="c:\programme\Avira\AntiVir Desktop\avgnt.exe" [2013-11-19 683576]
"ApnTBMon"="c:\programme\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe" [2013-10-23 1673680]
"SunJavaUpdateSched"="c:\programme\Gemeinsame Dateien\Java\Java Update\jusched.exe" [2013-07-02 254336]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\
Microsoft Office.lnk - c:\programme\Microsoft Office\Office\OSA9.EXE -b -l [2000-1-21 65588]
NDAS Geräte-Manager.lnk - c:\programme\NDAS\System\ndasmgmt.exe /startup [2010-1-13 283112]
TMMonitor.lnk - c:\programme\ArcSoft\TotalMedia 3.5\TMMonitor.exe [2010-5-22 258048]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2005-07-05 22:45 28672 ----a-w- c:\windows\system32\notifyf2.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2005-11-30 19:16 24576 ----a-w- c:\windows\system32\tphklock.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /r \??\f:\0autocheck autochk *\0OODBS
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\IBMTOOLS\\Updater\\jre\\bin\\javaw.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Programme\\Support.com\\Bin\\tgcmd.exe"=
"c:\\Programme\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Programme\\SiSoftware\\SiSoftware Sandra Lite 2011.SP1\\RpcAgentSrv.exe"=
"c:\\Programme\\SiSoftware\\SiSoftware Sandra Lite 2011.SP1\\WNt500x86\\RpcSandraSrv.exe"=
"c:\\Programme\\NetGear\\ProSafe Plus Utility\\ProSafe Plus Utility.exe"=
"c:\\Programme\\NetGear\\ProSafe Plus Utility\\NetGearServer.exe"=
"c:\\Programme\\NetGear\\ProSafe Plus Utility\\NsdpManager.exe"=
"c:\\Programme\\Belkin\\Belkin USB Print and Storage Center\\Connect.exe"=
"c:\\Programme\\Sybase\\SQL Anywhere 9\\win32\\dbsrv9.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"19540:UDP"= 19540:UDP:SXUPTP
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
.
R0 fltsrv;Acronis Storage Filter Management;c:\windows\system32\drivers\fltsrv.sys [11.04.2012 14:08 77696]
R0 ndasfs;ndasfs;c:\windows\system32\drivers\ndasfs.sys [13.01.2010 09:12 562152]
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [04.09.2013 13:05 37352]
R1 HWiNFO32;HWiNFO32 Kernel Driver;c:\programme\HWiNFO32\HWiNFO32.SYS [06.03.2011 01:00 20088]
R1 ndasfat;NDAS FAT File System Service;c:\windows\system32\drivers\ndasfat.sys [13.01.2010 09:12 461288]
R1 ndasrofs;NDAS ROFS File System Service;c:\windows\system32\drivers\ndasrofs.sys [13.01.2010 09:12 791528]
R2 drhard;drhard;c:\windows\system32\drivers\drhard.sys [06.03.2011 02:24 23600]
R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [25.06.2010 18:07 35088]
R3 AVMWAN;NDIS WAN CAPI Treiber;c:\windows\system32\drivers\avmwan.sys [16.07.2002 01:00 37568]
R3 FXUSBASE;Teledat X120 (WinXP/2000);c:\windows\system32\drivers\fxusbase.sys [16.07.2002 01:00 498672]
R3 hpusbfd;Hewlett-Packard USB Filter Class;c:\windows\system32\drivers\hpusbfd.sys [25.05.2009 15:46 7552]
S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\drivers\dc3d.sys [09.05.2012 16:29 45288]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\programme\Lavasoft\Ad-Aware\KernExplorer.sys --> c:\programme\Lavasoft\Ad-Aware\KernExplorer.sys [?]
S3 LucentSoftModem;Lucent Technologies Soft Modem;c:\windows\system32\drivers\LTSM.sys [01.10.2002 08:44 802683]
S3 MAFW;Service for M-Audio FireWire;c:\windows\system32\drivers\mafw.sys [12.12.2010 21:28 192392]
S3 NETPPPOI;PPP over ISDN;c:\windows\system32\drivers\NETPPPOI.SYS [23.05.2009 23:53 259072]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys --> c:\windows\system32\drivers\nmwcdnsu.sys [?]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys --> c:\windows\system32\drivers\nmwcdnsuc.sys [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-12-06 02:42 1210320 ----a-w- c:\programme\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2013-12-11 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-11 21:29]
.
2013-12-05 c:\windows\Tasks\BMMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\BMMTASK.EXE [2009-05-21 23:31]
.
2013-12-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programme\Google\Update\GoogleUpdate.exe [2013-11-15 21:29]
.
2013-12-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programme\Google\Update\GoogleUpdate.exe [2013-11-15 21:29]
.
2013-12-11 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-3264421748-380149622-3910952666-1004.job
- c:\progra~1\Real\______~1\realupgrade.exe [2010-11-05 10:33]
.
2013-12-10 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-3264421748-380149622-3910952666-1004.job
- c:\progra~1\Real\______~1\realupgrade.exe [2010-11-05 10:33]
.
.
------- Zusätzlicher Suchlauf -------
.
IE: Bild in &Microsoft PhotoDraw öffnen - c:\progra~1\MICROS~3\Office\1031\phdintl.dll/phdContext.htm
LSP: c:\programme\Avira\AntiVir Desktop\avsda.dll
TCP: Interfaces\{A29C7FE0-06D5-4939-85EE-10AC7B3EB02A}: NameServer = 192.168.121.252,192.168.121.253
TCP: Interfaces\{B54CB423-672B-427E-8E56-2233D6FB9A46}: NameServer = 192.168.1.2
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\dokumente und einstellungen\Neum\Anwendungsdaten\Mozilla\Firefox\Profiles\it7ytsqx.default\
FF - prefs.js: browser.startup.homepage - www.gmx.de
FF - ExtSQL: 2013-10-31 21:38; {73a6fe31-595d-460b-a920-fcc0f8843232}; c:\dokumente und einstellungen\Neum\Anwendungsdaten\Mozilla\Firefox\Profiles\it7ytsqx.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
FF - ExtSQL: 2013-10-31 21:38; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\dokumente und einstellungen\Neum\Anwendungsdaten\Mozilla\Firefox\Profiles\it7ytsqx.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
SafeBoot-Wdf01000.sys
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2013-12-11 22:28
Windows 5.1.2600 Service Pack 3 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
tgcmd = "c:\programme\Support.com\bin\tgcmd.exe" /server?ver
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,c1,43,65,99,a6,ce,a6,48,99,41,4e,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,c1,43,65,99,a6,ce,a6,48,99,41,4e,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG08.00.00.01WORKSTATION"="6152A02BDDF17CE9998BC00FD8333D54B68A015F02258B4480D62E7111E2C80269C5C4628504EFD079BC9C8835EAAC37048B6705AE23C04FB34DF85BE650B1A66365E41ABC2C573740FE719AC51427E14CA94845F4AAE0851B7E107184827BA376D3BB4C3A61ED8EBE0443D57606C3ABA3CA96E7959301CA309FF1562074D40324B7F2144BDD21AA95860BEEC85E4C54F15538DBE87C69E33FE813D107632535BA3CAB31D1A294443CBF363FD2FC42FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933C038D530D6EB3452A2D97226D213B555A6171C11EC38DE3D6A9A726AA28811D492A04A1C8EBB38B7166762CBD798AC2246B93B5F92A1AB110E1D72786430BB31A53A87A68486006B5819AF613D2B144ED3A6C0518F9EFC410C0E24F3D6D924072CE1E082099F69169C14AE31FA193DBA903E1CB8BF4E558BAC38CA3513DC642FB786ADD44E92ED6E5C0DE4CDFAC4229AFE18A63367064DC39B392C8753265539BA6AC2342902C8DF758ADB3E4CA37FD785A2B5D3EBB2C36FE703922CF7B597670FA4FB3012237B0AA8E89E7B1EBF568CED9E2A23D8D1DBC5835ACD55069E0DB0701FBA49A63EC9411D58BEF2C838EC8C68A0639A5D78F9B648DA2F2CA30CDDBEFE9AE1F2A7323B0C59DCCF88C5404B59051149A9CACCC86270708ECD9D3774F0BEA7D718F76E1C274C4DEB11B11CBD2DBA2D44B21A0BB79F9B5E46C7E4F001581A2E0A94A3797C00C755AE5650265773E584C08EE48177F64B39B49F8C9FF43EDBE7E6BAD5EC313C00753997854EEC4D42FCB207EA94FE266AEABC4E4BBA091A3465634EDFF451331001B0855D951710734F0FDB0EBA071E4233C43D7ECCB89CB8087508B6D23A6E73A03CC68493B24301884EBFD57E90850321B7CEA577C1A7E0079A1672DD8BAF8D4F8975CCF06223D308EFD86D805A353F9B83D5E4EE28D089EC5019D07C296AA15C4A9FACEB89A13A05F34223736DBB6EDC1C9B047B326473991C26B2ADBAC3DA6C30C63C5851E06706E00DE91F92596C71F75A6DF8EB5FC13F05C69D81AE1AC5F677603D1C28BC7168413AD95E5783F83D114334D824F57DE296F5389FB1FA54485AD80EB03F3E53DDA0C12C200FE3B673E579899DED0C14E1E02851BEBB2B5B7F990CB5A40AA86A69918D40E8CF59AC9F79164661A0BE5469763F5A2E02229410FACD5E1AC3EE79E5AAFD1A4EF2F3489FD2A4E54F575CF37DEF16E54D810A9D43C6615548E73BA67E0466DEFC18F957A47B260927F1E40AF3E978AF91FAC3F63349038DF738E77D35BC0B5BB31FE48CB3830CF3BE1291947702A79186F26286D052619C883B07EADDF42A7DC4306081287DC08C7DA0CCF208DC590FC7AFAD165EB99B3BECB7DB432254F0D69834D1AF"
"OODEFRAG10.00.00.01WORKSTATION"="7EC9439BEDA7EA89F0AFA73825271254445633E989A5B7FD762E4EDA768AC571CF617BF160FB320A07575C57488D00097F04B448BDB5594A130A94BBF19535556BA9FE585C148BB86D012DB7E6459FB5B59ED9FA37A1D4BF1DDF2130FB8D93C35AA1EE8554B7C3C729C1FE4E3F3BCEDB027066569C1A38CBEA4D388A4308C435CD5BB1E8A1FE3061E0C076C571ABF2EEA75562E1F6A21A51F705E3CFD8ECAC1C9680F123FDD725A0613B81FC812B72D80ABF19D9341511A55FCDF037347836D8AB4A1D0B0905FE9499014C86D620B97631B59C2B261ABC13E581702DB03C4FC3A909E429469B9B439E76CC2ABFC437994C4DBFFB80B43B58FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808A2D97226D213B555BA7FD869164D6794A6171C11EC38DE3DD88A0474420B15142B18AC557C61AF6A39C608339B4AE162B4FEE19922C29A6926B7A44B43CB9C8422CC6893E3D713879C9790ECAF1E3D2739E5787239AB1D513E3736282F4E45DA89CFE58E9A4E2A009D150704B5730DA8BA41ED7D4B64EE0E8E64C309AC4517A0E3320F21AF3AACC5F8255753C4A65CE8D1EB50B2984E89D0262E1C21C4B89DD0DB1995DA9468574691C1B3E4D7E7B6DF365670BA4221EB3D391AD1D4E181E85FBEBEEC009D786BDDEC7A107ACBBC2E764A02E4F2D1E41A6C9F40BB4155CF0B30FA6F4E06055F2D5E3571278864FCD90E0E0789EB30F799E8554DF53454261E1BA78C351CE7E2E30F385C743847D5D2792991F96CAF8BF334FA01DF2E76D9BB6EFD8BE09DC7205E296885BAE37EC9B57D68DF9AEC01A63A4052AE9B68379885EB597656210A076C5B5ACAFD1F792AA5573946901C3EA1FC7745BF914C785E9C46BA68DDEC78DA62C5C91F08AB0B22C7B52DA9C45CE0AB54B4DFB16BF87E7FAAA8C894837C3F33998092096604E7AE45BBFD876740C8C5DA47CF91194071A2DA30CA40978070FCEE953822E8D3AA1F4B7F05EE6993B9C5ADF4EB07CD285DC25C6B2EC32EDA82F5C1015F9826FAD3190D8C418282D2DA5671F42AC801EC33AC63E1048D9FA34DB3F637533075104395BF6255792A3137F24B7226A26D7AC686280B801D07278F1DF79C01BC7659C0E01C728820A1113E6FE68EA1F412F65044E4D5FC0AC464E8EDB18CFAAA8754F69BE0A6C554681044F0F25CFE35B2B56DB1D820767B7E8E603793D37577503272BBCED69B8AC6F77FF1A0E5C66BD5C21DEDC9428D309B0E5FDA93B44C35395528882C543DC945CC0C3FA725A432C65CC46A7E04877847FCB291A866FC0A6ED9EC9FC2E0032D32C2E97AC20A683C94742DEFC1224EB9F22C8B67519029B062887B71DF34E4E2A043FA1AB07986CB1333819764CD6C6E511E7F3C8D539777C864F1C254F8"
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'winlogon.exe'(928)
c:\windows\system32\tphklock.dll
.
- - - - - - - > 'lsass.exe'(984)
c:\programme\Avira\AntiVir Desktop\avsda.dll
.
- - - - - - - > 'explorer.exe'(2328)
c:\windows\system32\msi.dll
c:\progra~1\ThinkPad\UTILIT~1\pwrmonit.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\programme\Avira\AntiVir Desktop\sched.exe
c:\programme\Belkin\Router Setup and Monitor\BelkinService.exe
c:\programme\Avira\AntiVir Desktop\avguard.exe
c:\programme\AskPartnerNetwork\Toolbar\apnmcp.exe
c:\windows\System32\Ati2evxx.exe
c:\programme\Belkin\Belkin USB Print and Storage Center\BkBackupScheduler.exe
c:\programme\Belkin\Belkin USB Print and Storage Center\Bkapcs.exe
c:\programme\Java\jre7\bin\jqs.exe
c:\programme\Sybase\SQL Anywhere 9\win32\dbsrv9.exe
c:\programme\NDAS\System\ndassvc.exe
c:\windows\system32\netdde.exe
c:\programme\CDBurnerXP\NMSAccessU.exe
c:\windows\system32\oodag.exe
c:\programme\TP-LINK\TP-LINK Wireless Configuration Utility\Service\RaRegistry.exe
c:\windows\System32\RegSrvc.exe
c:\programme\TomTom HOME 2\TomTomHOMEService.exe
c:\programme\Avira\AntiVir Desktop\avshadow.exe
c:\programme\Avira\AntiVir Desktop\AVWEBGRD.EXE
c:\windows\System32\wbem\wmiapsrv.exe
c:\windows\system32\RunDll32.exe
c:\programme\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
c:\programme\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
c:\windows\AGRSMMSG.exe
c:\programme\Belkin\Belkin USB Print and Storage Center\connect.exe
c:\programme\NDAS\System\ndasmgmt.exe
c:\programme\Belkin\Router Setup and Monitor\BelkinSetup.exe
c:\programme\Belkin\Router Setup and Monitor\dlnaPlugin.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2013-12-11 22:48:44 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2013-12-11 21:48
.
Vor Suchlauf: 27 Verzeichnis(se), 31.889.244.160 Bytes frei
Nach Suchlauf: 28 Verzeichnis(se), 31.847.841.792 Bytes frei
.
- - End Of File - - 287831FDECEA2EC4A982B7713873B467
AB67D479E4EE1CCAD757294B60DDB98F |